-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Description
It's unclear how to specify a mount option such as sec=sys. When using a NFSv4 volume from a modern operating system, the negotiation will naturally take the highest level of security that is available.
Unfortunately, if that resolves to krb5, an arbitrary container is unlikely to have a ticket or the ability to acquire one. In that case, the contents of the volume will either be inaccessible or mapped to nobody. sec=sys is not ideal, but sufficient in a controlled security context.
Apologies if this is already addressed and I missed it in the documentation.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels