Disable NFS over TLS
You can disable TLS encryption at any time. Disabling TLS is also a disruptive operation that requires remounting all clients.
| Disabling TLS requires a maintenance window. After TLS is disabled, all clients must be remounted without TLS mount options before data access can resume. |
-
Log in to the Management GUI and navigate to .
-
Click the NFS Transport Layer Security switch. The Disable TLS dialog warns that all clients with TLS connections will be interrupted and may need to be remounted. Click Disable TLS.
Disabling TLS is a cluster-wide operation. It usually takes 1–3 minutes; on a cluster where enabling TLS took about 30 minutes, disabling took under 2 minutes. Allow up to about 30 minutes on a large cluster.
-
After the process completes, remount each client using your standard NFS mount options, without the
xprtsecoption (or withxprtsec=none):Remount clientssudo umount /mnt/your_mount_point sudo mount <cluster_ip>:/<export_path> /mnt/your_mount_point -
Update
/etc/fstabto remove thexprtsec=mtlsoption from any persistent mount entries. After TLS is disabled, a mount that still requestsxprtsec=mtlsis refused (mount.nfs: access denied by server).