Search the docs

Enable or Disable TLS

Enabling or disabling TLS from the CLI carries the same disruption and client remount requirements as doing so from the GUI. See Workflow Overview before running either command.

TLS is enabled and disabled cluster-wide using the cluster-config command.

To enable TLS and require mutual authentication on all NFS connections:

cluster-config --nfs-tls-required

To disable TLS and revert all NFS connections to plaintext:

cluster-config --nfs-tls-forbidden

Enabling or disabling TLS typically takes 2–3 minutes, and up to about 30 minutes when the DSX data-portal mounts are restarted during the change. Both commands start a background task and wait for it for up to 5 minutes. If the task has not finished by then, the command returns an error with the message cluster-config: Task-based operation still running after 5 minutes. To monitor progress, use: task-list --id <task-id>. The task (named cluster-update) keeps running. The change is complete when the task reports COMPLETED with the status message Updated: [nfsTransportPolicy → TLS_REQUIRED_WITH_MUTUAL_AUTH] (or TLS_FORBIDDEN).

While the change runs, the task’s status message shows its progress, for example Updating NFS transport policy: Configuring metadata server, Updating NFS transport policy: Restarting metadata server, and Updating NFS transport policy: Configuring product nodes. Hammerspace makes up to three attempts to configure any node that fails before the task fails.

To return immediately without waiting, add --async, and monitor the task separately:

cluster-config --nfs-tls-required --async

To check the current TLS policy, look for the NFS transport policy line in the output of:

cluster-config --view
The cluster-config command also includes options for managing the management plane HTTPS certificate used by the GUI and REST API (--server-certificate-chain, --server-private-key, --server-certificate-reset). These options are unrelated to NFS over TLS and are not covered in this document.