Linux NFS development
 help / color / mirror / Atom feed
* GSSPROXY ( for NFS with sec=krb5, krb5i  , krb5p ) is development still active or is it being depreciated
@ 2025-03-12 23:29 Andrew J. Romero
  2025-03-13 11:30 ` Andrew J. Romero
  2025-09-04 17:52 ` GSSPROXY ( for NFS with sec=krb5, krb5i , krb5p ) is development still active or is it being depreciated Charles Hedrick
  0 siblings, 2 replies; 12+ messages in thread
From: Andrew J. Romero @ 2025-03-12 23:29 UTC (permalink / raw)
  To: linux-nfs@vger.kernel.org

Hi

I noticed that in newer versions of Linux 
( for example: Red Hat Enterprise v9 ), the 
parameter  use-gss-proxy 
(in [gssd] section of /etc/nfs.conf file )
no longer exists.  Why not ?


I have also read that some security specialists
( noted in stigviewer.com ) theorize that gssproxy
increases security risk.


gssproxy facilitates the reliable use of Kerberos secured
NFS storage by non-interactive processes.

What are the plans for gssproxy:

a) continue to actively maintain gssproxy
   ( and resolve any security concerns )

b) quickly replace gssproxy with another
   facility to allow non-interactive processes
   to access Kerberos secured
   NFS storage

c) Declare that non-interactive process access to
   Kerberos secured NFS storage is being depreciated
   and people should either revert back to kludgy kinit cron scripts
   and the flakey gss kernel context behavior of the past
   or seek non-NFS solutions.  

Thanks

Andy Romero
Fermilab / ITD


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2025-09-04 19:13 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-03-12 23:29 GSSPROXY ( for NFS with sec=krb5, krb5i , krb5p ) is development still active or is it being depreciated Andrew J. Romero
2025-03-13 11:30 ` Andrew J. Romero
2025-03-14 12:18   ` Benjamin Coddington
2025-03-14 14:45     ` Scott Mayhew
2025-03-14 14:57       ` Andrew J. Romero
2025-03-14 14:57     ` [nfs-utils PATCH] gssd.man: add documentation for use-gss-proxy nfs.conf option Scott Mayhew
2025-03-15 15:17     ` GSSPROXY ( for NFS with sec=krb5, krb5i , krb5p ) is development still active or is it being depreciated Steve Dickson
2025-03-15 15:33       ` Chuck Lever
2025-03-17 13:22       ` [nfs-utils PATCH v2] gssd.man: add documentation for use-gss-proxy nfs.conf option Scott Mayhew
2025-03-24 20:29         ` Steve Dickson
2025-09-04 17:52 ` GSSPROXY ( for NFS with sec=krb5, krb5i , krb5p ) is development still active or is it being depreciated Charles Hedrick
2025-09-04 19:13   ` Andrew Romero

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox