Search the docs

Prerequisites

Before enabling TLS, verify that all components in your environment meet the following requirements.

Hammerspace Cluster

  • Hammerspace 5.3 or later.

  • The cluster must not have NFS referral shares configured.

  • All cluster nodes must be reachable and healthy before starting the enablement process.

Linux Clients

Each Linux client that will mount NFS shares over TLS must meet the following requirements:

Component Minimum version

Linux kernel

6.12

nfs-utils

2.5.4

ktls-utils

1.0.0-rc1

Enterprise Linux distribution

RHEL 10.1, Rocky Linux 10.1, or later

In addition:

  • Mutual (two-way) trust must be established between the client and Hammerspace. The client must present an X.509 certificate that Hammerspace trusts — either issued directly to the client or signed by a certificate authority that Hammerspace trusts — and the Hammerspace root CA certificate (or the customer’s own CA certificate) must be installed in the client’s trust store. For how to establish this trust, see Reference: Certificate Trust Model.

  • The tlshd service (part of ktls-utils) must be installed and configured on each client. tlshd manages the TLS handshake for the Linux NFS client and kernel.

Third-Party Backend Storage

  • Backend storage must support NFS over TLS with mutual authentication. When TLS is required, Hammerspace mounts every backend storage volume with TLS, and a volume on storage that does not support it becomes unavailable. Enablement does not check the volumes for you: the Volumes step of the Enable TLS wizard shows their status, but does not stop you from continuing.

  • Confirm TLS support with your storage vendor before proceeding. See Reference: Supported Third-Party Backend Storage for known-supported systems.

Backup and External Storage Servers

When TLS is required, every external NFS storage server and every backup server the cluster touches must also be TLS-enabled. A non-TLS backup target fails to mount once the cluster policy requires TLS, with the error:

mount.nfs: access denied by server while mounting <ip>:/backup, error code: 32

Verify TLS capability on all backup servers — not just primary backend storage — before starting the enablement process.