Re: Will NFSv4 be accepted?

From: Dax Kelson (dax@gurulabs.com)
Date: Wed Aug 14 2002 - 20:51:56 EST


Q for Linus: What's the prospect of adding crypto to the kernel?

(more below)

On 15 Aug 2002, Alan Cox wrote:

> Ok item #1 you authenticate with the server and get a cryptographic key
> for use as credentials. This solves the bad client problem. Kerberos,
> gssapi etc will do the job

Right, I do understand that Kerberized/GSS NFS is not exclusive to NFSv4.
However, right now, there is only one way to get Kerberized NFS. The CITI
NFSv4 patches.

Those patches are, in their estimation, ready for inclusion. NFSv3
support is "coming down the pipeline".

I would rather see Kerberos V5 NFS data integrity and privacy support
first (also in the pipeline). What the current status of including crypto
in the kernel?

> Item #2 is a bug in our NFS page cache handling. Its not legal in NFS to
> assume we can share caches between processes unless they have the same
> NFS credentials for the query.

I wasn't aware of this.

Thanks,
Dax

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Thu Aug 15 2002 - 22:00:38 EST