Search the docs

Disable NFS over TLS

You can disable TLS encryption at any time. Disabling TLS is also a disruptive operation that requires remounting all clients.

Disabling TLS requires a maintenance window. After TLS is disabled, all clients must be remounted without TLS mount options before data access can resume.
  1. Log in to the Management GUI and navigate to Administration  TLS.

  2. Click the NFS Transport Layer Security switch. The Disable TLS dialog warns that all clients with TLS connections will be interrupted and may need to be remounted. Click Disable TLS.

    Disabling TLS is a cluster-wide operation. It usually takes 1–3 minutes; on a cluster where enabling TLS took about 30 minutes, disabling took under 2 minutes. Allow up to about 30 minutes on a large cluster.

  1. After the process completes, remount each client using your standard NFS mount options, without the xprtsec option (or with xprtsec=none):

    Remount clients
    sudo umount /mnt/your_mount_point
    sudo mount <cluster_ip>:/<export_path> /mnt/your_mount_point
  2. Update /etc/fstab to remove the xprtsec=mtls option from any persistent mount entries. After TLS is disabled, a mount that still requests xprtsec=mtls is refused (mount.nfs: access denied by server).