<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:19:33 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-15582] RFI for lustre encryption</title>
                <link>https://jira.whamcloud.com/browse/LU-15582</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;We are running a lustre cluster and have been requested to determine if communications between clients and servers is encrypted. Requesting assistance in determining with if our client and servers lustre communications is encrypted.&#160;&lt;/p&gt;</description>
                <environment>RHEL 7</environment>
        <key id="68798">LU-15582</key>
            <summary>RFI for lustre encryption</summary>
                <type id="6" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11315&amp;avatarType=issuetype">Story</type>
                                            <priority id="3" iconUrl="https://jira.whamcloud.com/images/icons/priorities/major.svg">Major</priority>
                        <status id="1" iconUrl="https://jira.whamcloud.com/images/icons/statuses/open.png" description="The issue is open and ready for the assignee to start work on it.">Open</status>
                    <statusCategory id="2" key="new" colorName="default"/>
                                    <resolution id="-1">Unresolved</resolution>
                                        <assignee username="sebastien">Sebastien Buisson</assignee>
                                    <reporter username="rseal">Ryan Seal</reporter>
                        <labels>
                    </labels>
                <created>Tue, 22 Feb 2022 17:59:34 +0000</created>
                <updated>Mon, 28 Feb 2022 12:46:30 +0000</updated>
                                            <version>Lustre 2.12.8</version>
                                                        <due></due>
                            <votes>0</votes>
                                    <watches>3</watches>
                                                                            <comments>
                            <comment id="327041" author="pjones" created="Tue, 22 Feb 2022 23:32:27 +0000"  >&lt;p&gt;S&#233;bastien&lt;/p&gt;

&lt;p&gt;Could you please talk to the options in this area, both in 2.12.x and more current releases&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;Peter&lt;/p&gt;</comment>
                            <comment id="327592" author="sebastien" created="Mon, 28 Feb 2022 12:46:30 +0000"  >&lt;p&gt;Hi Ryan,&lt;/p&gt;

&lt;p&gt;In Lustre 2.12, you have two options to get the client/server communications encrypted:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;you can configure Kerberos for Lustre, with the &lt;tt&gt;krb5p&lt;/tt&gt; flavor. It ensures privacy of both RPC messages and bulk data. Please refer to the Lustre documentation for full details, at &lt;a href=&quot;https://doc.lustre.org/lustre_manual.xhtml#managingSecurity.kerberos&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://doc.lustre.org/lustre_manual.xhtml#managingSecurity.kerberos&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;you can make use of the Shared-Secret Key (SSK) feature, which provides privacy of both RPC messages and bulk data when the &lt;tt&gt;skpi&lt;/tt&gt; flavor is selected. For full details, please refer to &lt;a href=&quot;https://doc.lustre.org/lustre_manual.xhtml#lustressk&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://doc.lustre.org/lustre_manual.xhtml#lustressk&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;In Lustre 2.14/2.15, you get one more option thanks to the client-side encryption feature. Its purpose is to protect data at rest, but as it is implemented on Lustre client side, most of the traffic between clients and servers gets encrypted when accessing an encrypted directory. Please note that some information remains unencrypted even for encrypted files, such as timestamps, access rights, file owner, extended attributes, but depending on your use case it might be fine.&lt;br/&gt;
The documentation for client-side encryption is available here:&lt;br/&gt;
&lt;a href=&quot;https://doc.lustre.org/lustre_manual.xhtml#managingSecurity.clientencryption&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://doc.lustre.org/lustre_manual.xhtml#managingSecurity.clientencryption&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Please let me know if you need more information.&lt;br/&gt;
Cheers,&lt;br/&gt;
Sebastien.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i02j0v:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>