Commit 239ff5d
committed
tlshd: Return a non-zero peerid
NFSD depends on seeing a non-zero peerid to know when the session
has been authenticated (mTLS). Currently NFSD does not read or
parse the remote peer's certificate.
If tlshd fails to link the certificate onto the USER_SPEC keyring,
it still needs to return a peerid that is non-zero to show that
the remote peer presented a trusted certificate.
Hack city. But this "fix" is compatible with older kernels and
ktls-utils releases. A more complete fix is forthcoming.
Signed-off-by: Chuck Lever <[email protected]>1 parent b8a754f commit 239ff5d
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
224 | 224 | | |
225 | 225 | | |
226 | 226 | | |
| 227 | + | |
| 228 | + | |
227 | 229 | | |
228 | 230 | | |
229 | 231 | | |
| |||
0 commit comments