Search the docs

Reference: Client Requirements

Table 1. Client requirement for TLS

Component

Minimum version

Notes

Linux kernel

6.12

Required for RFC 9289 support via the kernel NFS client and knfsd with tlshd.

nfs-utils

2.5.4

TLS-aware NFS userspace utilities.

ktls-utils

1.0.0-rc1

Provides tlshd, the TLS handshake daemon required by the kernel NFS client.

RHEL / Rocky Linux

10.1

Required for NFSv4.2 over TLS. NFSv3 over TLS may work on some earlier distributions with the correct kernel and packages.

Ubuntu

TBD

Minimum version to be confirmed.

Supported NFS versions over TLS: NFSv4.1 and NFSv4.2 to the cluster (the Anvil), and NFSv3 and NFSv4.2 to DSX data-portal addresses. The Anvil does not serve NFSv4.0 or NFSv3, with or without TLS. With NFSv3, the MOUNT, NLM (locking), and NSM protocols are not encrypted.

Supported TLS versions: TLS 1.2 and TLS 1.3. TLS 1.3 is preferred when both the client and server support it. TLS 1.2 is available for environments with clients that do not yet support TLS 1.3.