Thread (2 messages) 2 messages, 1 author, 1d ago

[PATCH RFC v3 0/5] NFS: isolate mTLS client credentials by network namespace

flat view
WARM1d

From: Chuck Lever <cel@kernel.org>
Date: 2026-10-06 15:24:28
Also in: keyrings, linux-doc, linux-nfs

An xprtsec=mtls mount names its client certificate and private key
by keyring serial number. tlshd reads those keys with its own
credentials. Each key has to grant user read permission, and any
tlshd on the host that learns a serial number can read it.

The RFC thread asked whether the user or mount namespace is a
better binding than the network namespace. tlshd services the
handshake socket of one network namespace, so that is the namespace
tlshd already lives in.

  https://lore.kernel.org/linux-nfs/20260602154740.49861-1-cel@kernel.org/ (local)

After this series each network namespace has its own .nfs keyring,
and the keyring's serial number travels with each handshake (patches
3-4). Possessing that keyring lets tlshd read a key that does not
grant user read permission. tls_handshake_accept() and tlshd already
link a keyring named in the handshake. The handshake genetlink ABI
and the cert_serial= and privkey_serial= mount options are not
changed.

The owner of the network namespace's user namespace now owns the
keyring, so global root on the host cannot write to a container's
keyring from outside.

nfstlskey, the provisioning tool that consumes the key type, is in
https://github.com/linux-nfs/ktls-utils/ .

Tested on v7.3-rc4 plus this series, on one Fedora VM as both NFS
client and NFSD, with tlshd from ktls-utils 1.4.0.

---
Changes in v3:
- Rebased on v7.3-rc6
- No reviews received; stripped the "RFC" Subject prefix
- Link to v2: https://patch.msgid.link/20260925-nfs-mtls-identity-v2-0-aa3ad17dd6c8@kernel.org

Changes in v2:
- Write "serial number" rather than "serial" throughout (Randy)
- Give the .nfs keyring to the netns's user_ns owner (sashiko)
- Link to v1: https://patch.msgid.link/20260918-nfs-mtls-identity-v1-0-197e568d78a7@kernel.org

---
Chuck Lever (5):
      NFS: name the init_nfs_fs() error labels
      NFS: allocate the .nfs keyring per network namespace
      SUNRPC: pass a keyring serial number to the TLS handshake
      NFS: name the namespace .nfs keyring in the x509 handshake
      NFS: add a key type that reveals the namespace .nfs keyring serial number

 Documentation/filesystems/nfs/index.rst   |   1 +
 Documentation/filesystems/nfs/keyring.rst |  69 ++++++++++
 fs/nfs/client.c                           |   9 +-
 fs/nfs/fs_context.c                       |   1 +
 fs/nfs/inode.c                            | 211 ++++++++++++++++++++++--------
 fs/nfs/netns.h                            |   9 ++
 fs/nfs/nfs3client.c                       |   1 +
 fs/nfs/nfs4client.c                       |   1 +
 include/linux/sunrpc/xprt.h               |   1 +
 net/sunrpc/xprtsock.c                     |   1 +
 10 files changed, 248 insertions(+), 56 deletions(-)
---
base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
change-id: 20260917-nfs-mtls-identity-04c14f6f348d

Best regards,
--  
Chuck Lever [off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help