Remounting an Ubuntu Client
| NFS over TLS requires Linux kernel 6.12 or later. Ubuntu system administrators should verify their kernel version before proceeding: |
uname -r
Ubuntu 25.04 ships kernel 6.14 and meets this requirement out of the box. Ubuntu 24.04 LTS ships kernel 6.8 by default; administrators on 24.04 LTS should verify whether their system is running the Hardware Enablement (HWE) kernel, which tracks more recent upstream releases:
dpkg -l linux-image-generic-hwe-24.04
These instructions apply to Ubuntu 25.04 and later, and to Ubuntu 24.04 LTS with a kernel that meets the ≥ 6.12 requirement.
Prerequisites
Verify the following before remounting:
-
Install the required packages:
sudo apt install nfs-common ktls-utilsnfs-commonprovides the Ubuntu equivalent ofnfs-utils(themount.nfsand related utilities).ktls-utilsprovidestlshd, the TLS handshake daemon required by the Linux kernel NFS client.Check the installed version with tlshd --version(orjournalctl -u tlshd, which logsBuilt from ktls-utils <version>). Ubuntu 24.04 LTS packagesktls-utils0.9, which is below the minimum in Reference: Client Requirements. With 0.9,tlshdcan only verify the Hammerspace server certificate when the server address reverse-resolves to a name in that certificate, so mounts fail withgnutls: Error in the certificate. (-43)in thetlshdjournal. Install a currentktls-utilsrelease (built from source if your distribution does not package one) before continuing.
-
Install the Hammerspace cluster CA certificate in the Ubuntu trust store. This is the certificate that provides; it is the issuer of every Anvil and DSX certificate, so the client must trust it whichever CA issued the client’s own certificate:
sudo cp hammerspace-ca.crt /usr/local/share/ca-certificates/hammerspace-ca.crt sudo update-ca-certificatesThe
update-ca-certificatescommand adds the certificate to/etc/ssl/certs/ca-certificates.crt, whichtlshduses as its default trust store. -
Configure
tlshdwith the client certificate and private key. Edit/etc/tlshd.confand populate the[authenticate.client]section:[authenticate.client] x509.truststore= /etc/ssl/certs/ca-certificates.crt x509.certificate= /etc/ssl/hs-tls/cert.pem x509.private_key= /etc/ssl/private/hs-tls/key.pemIn ktls-utils1.3.0 and later, the default configuration file is/etc/tlshd/config. If/etc/tlshd.confexists,tlshdreads it instead and logsPlease relocate /etc/tlshd.conf to /etc/tlshd/config. Edit whichever file your distribution uses, and restarttlshdafterward.Replace the certificate and key paths with the actual locations of your client certificate and private key. If the client certificate was issued by an intermediate CA, put the intermediate CA certificate after the client certificate in the same file (
x509.certificate), or add the intermediate CA to the Hammerspace trust store withcert-add --trust-intermediate-ca; Hammerspace must be able to build the chain from what the client presents to a CA it trusts. Restrict access to the private key file:sudo chmod 600 /etc/ssl/private/hs-tls/key.pem -
Enable and start the
tlshdservice:sudo systemctl enable --now tlshd.service -
Verify that
tlshdis running without errors:sudo journalctl -u tlshd --no-pager -n 20Confirm there are no errors related to certificate loading or TLS handshake failures before proceeding.
Procedure
-
If the share is currently mounted, stop any processes using it, then unmount:
sudo umount /mnt/your_mount_pointIf the unmount fails because the mount point is busy, use fuser -m /mnt/your_mount_pointto identify and stop the active processes before retrying. -
Remount the share with the
xprtsec=mtlsoption to require mutual TLS authentication:sudo mount -o xprtsec=mtls <cluster_ip>:/<export_path> /mnt/your_mount_point -
To ensure the share remounts automatically with TLS after a system reboot, add or update the entry in
/etc/fstab:<cluster_ip>:/<export_path> /mnt/your_mount_point nfs xprtsec=mtls,_netdev 0 0-
xprtsec=mtls— Requires mutual TLS authentication for the NFS connection. -
_netdev— Ensures the network is available before the system attempts to mount the share at boot time.
-
Verify the TLS Connection
After remounting, verify that the connection is using TLS:
-
Check the connection status. Connections to the Anvil use port 2049. With a pNFS mount (NFSv4.2), data connections go directly to DSX nodes on port 3049. Check both:
sudo ss -tni | grep -E -A1 ':(2049|3049)\b'A connection that uses TLS shows
tcp-ulp-tlsin its details, for exampletcp-ulp-tls version: 1.3 cipher: aes-gcm-256. Run the command as root: on some kernels the TLS details are omitted for other users. -
Check the NFS mount statistics. Confirm that
xprtsec=mtlsappears in the reported mount options:nfsstat -m -
Review
tlshdlogs to confirm the TLS handshake completed successfully:sudo journalctl -u tlshd --no-pager -n 20