Using TLS for End-to-End Encryption
Hammerspace 5.3 supports end-to-end, data-path encryption using NFS over mutual Transport Layer Security (mTLS) as a technology preview. With TLS enabled, NFS protocol traffic between clients, the Hammerspace cluster, and backend storage systems is encrypted and mutually authenticated. SMB and S3 client traffic is not covered.
This feature implements IETF RFC 9289, which defines RPC-with-TLS for NFS. It provides wire-level confidentiality and mutual authentication: both the client and the server present X.509 certificates to verify each other’s identity before exchanging any data. This protects against eavesdropping and man-in-the-middle attacks on NFS traffic — threats that standard NFS has no native defense against.
TLS secures the transport channel and authenticates the host, not the user. User identity still comes from the share’s RPC security flavor — AUTH_SYS, or Kerberos where it is configured. Per-user certificate authentication is outside the scope of this release.
NFS over TLS is an all-or-nothing solution. When enabled, every NFS connection in the environment — from clients to the cluster, from the cluster to backend storage, and between internal cluster components — must use TLS. Partial or per-share TLS configurations are not supported. Within a global file system, the enable wizard recommends enabling TLS on every GFS site, but does not enforce it.
This section includes the following subsections: