Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Package Request: ktls-utils #1538

Open
1 of 4 tasks
JeWe37 opened this issue Sep 5, 2024 · 0 comments
Open
1 of 4 tasks

New Package Request: ktls-utils #1538

JeWe37 opened this issue Sep 5, 2024 · 0 comments

Comments

@JeWe37
Copy link

JeWe37 commented Sep 5, 2024

Package name and purpose
ktls-utils provides the userspace component of kernel TLS. This is used for instance with the NFS xprtsec option in order to enable RPC-over-TLS for NFS.

Impact of adding this package to the Flatcar OS image

The package improves on the following core values:

  • Secure by default
  • Always up to date
  • Improve container experience
  • Operate at scale / automation / telemetry

The package will increase the image size by: 0.1 MBytes.

How might this package increase the attack surface:
kTLS isn't used so far, so arguably problems in kTLS could present problems. On the other hand however, by using kTLS one could circumvent the need for Kerberos encryption, which is not as ubiquitous as TLS.

Benefits of adding this package
TLS is simpler to deploy than Kerberos for securing NFS shares, only requiring the distribution of x509 certificates and even permitting authentication via mtls.

Additional information
None

@JeWe37 JeWe37 changed the title New Package Request: [ktls-utils] New Package Request: ktls-utils Sep 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: 📝 Needs Triage
Development

No branches or pull requests

2 participants