Prerequisites
Before enabling TLS, verify that all components in your environment meet the following requirements.
Hammerspace Cluster
-
Hammerspace 5.3 or later.
-
The cluster must not have NFS referral shares configured.
-
All cluster nodes must be reachable and healthy before starting the enablement process.
Linux Clients
Each Linux client that will mount NFS shares over TLS must meet the following requirements:
| Component | Minimum version |
|---|---|
Linux kernel |
6.12 |
|
2.5.4 |
|
1.0.0-rc1 |
Enterprise Linux distribution |
RHEL 10.1, Rocky Linux 10.1, or later |
In addition:
-
Mutual (two-way) trust must be established between the client and Hammerspace. The client must present an X.509 certificate that Hammerspace trusts — either issued directly to the client or signed by a certificate authority that Hammerspace trusts — and the Hammerspace root CA certificate (or the customer’s own CA certificate) must be installed in the client’s trust store. For how to establish this trust, see Reference: Certificate Trust Model.
-
The
tlshdservice (part ofktls-utils) must be installed and configured on each client.tlshdmanages the TLS handshake for the Linux NFS client and kernel.
Third-Party Backend Storage
-
Backend storage must support NFS over TLS with mutual authentication. When TLS is required, Hammerspace mounts every backend storage volume with TLS, and a volume on storage that does not support it becomes unavailable. Enablement does not check the volumes for you: the Volumes step of the Enable TLS wizard shows their status, but does not stop you from continuing.
-
Confirm TLS support with your storage vendor before proceeding. See Reference: Supported Third-Party Backend Storage for known-supported systems.
Backup and External Storage Servers
When TLS is required, every external NFS storage server and every backup server the cluster touches must also be TLS-enabled. A non-TLS backup target fails to mount once the cluster policy requires TLS, with the error:
mount.nfs: access denied by server while mounting <ip>:/backup, error code: 32
Verify TLS capability on all backup servers — not just primary backend storage — before starting the enablement process.