public inbox for kernel-tls-handshake@lists.linux.dev
 help / color / mirror / Atom feed
* support keyrings for NFS TLS mounts v2
@ 2025-05-15 11:50 Christoph Hellwig
  2025-05-15 11:50 ` [PATCH 1/2] NFS: support the kernel keyring for TLS Christoph Hellwig
                   ` (3 more replies)
  0 siblings, 4 replies; 24+ messages in thread
From: Christoph Hellwig @ 2025-05-15 11:50 UTC (permalink / raw)
  To: Chuck Lever, Trond Myklebust
  Cc: Anna Schumaker, David Howells, Jarkko Sakkinen, linux-nfs,
	kernel-tls-handshake, keyrings

Hi all,

this series allows storing the key and certificate for NFS over
TLS mounts in the keyring and be specified using a mount option.
This way they don't need to be hardcoded in the global tlshd.conf
configuration file and can even be different per-mount.

Note that for now the .nfs keyring still needs to be added to
tlshd.conf, but that should go away with the handshake enhacement
from Hannes.

Changes since v1:
 - don't depend on nfsv4 for the keyring
 - fix compile when the kernel keyring is disabled

^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2025-07-10 13:14 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-05-15 11:50 support keyrings for NFS TLS mounts v2 Christoph Hellwig
2025-05-15 11:50 ` [PATCH 1/2] NFS: support the kernel keyring for TLS Christoph Hellwig
2025-05-15 12:51   ` Jarkko Sakkinen
2025-05-15 14:46     ` Hannes Reinecke
2025-05-16  5:17       ` Christoph Hellwig
2025-05-16 17:01       ` Jarkko Sakkinen
2025-05-16 11:47   ` Sagi Grimberg
2025-05-15 11:50 ` [PATCH 2/2] nfs: create a kernel keyring Christoph Hellwig
2025-05-16 11:47   ` Sagi Grimberg
2025-05-16 17:03     ` Jarkko Sakkinen
2025-05-17  9:45       ` Sagi Grimberg
2025-06-02 15:25         ` Christoph Hellwig
2025-06-04 16:42           ` Jarkko Sakkinen
2025-06-05  4:28             ` Christoph Hellwig
2025-06-06 16:47               ` Jarkko Sakkinen
2025-06-09  4:01                 ` Christoph Hellwig
2025-06-09 21:28                   ` Jarkko Sakkinen
2025-06-10  4:34                     ` Christoph Hellwig
2025-05-17 18:39   ` kernel test robot
2025-05-15 12:31 ` support keyrings for NFS TLS mounts v2 Chuck Lever
2025-05-16  5:16   ` Christoph Hellwig
2025-05-16 11:46     ` Sagi Grimberg
2025-07-10  7:25 ` Christoph Hellwig
2025-07-10 13:14   ` Trond Myklebust

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox