<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nfs kerberos encryption types in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Nfs-kerberos-encryption-types/m-p/134382#M29413</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am testing our clustered ontap with a nfs/krb5 client from Centos7. To our older ontap 7 filers we used arcfour encryption. Is there anyone who knows what has changed in ontap 9.2 ?&lt;/P&gt;&lt;P&gt;Is AES256 the only one supported and has anyone have a nfs/krb5 system that is working ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings, Richard.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 14:37:23 GMT</pubDate>
    <dc:creator>rsmits1074</dc:creator>
    <dc:date>2025-06-04T14:37:23Z</dc:date>
    <item>
      <title>Nfs kerberos encryption types</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Nfs-kerberos-encryption-types/m-p/134382#M29413</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am testing our clustered ontap with a nfs/krb5 client from Centos7. To our older ontap 7 filers we used arcfour encryption. Is there anyone who knows what has changed in ontap 9.2 ?&lt;/P&gt;&lt;P&gt;Is AES256 the only one supported and has anyone have a nfs/krb5 system that is working ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings, Richard.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:37:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Nfs-kerberos-encryption-types/m-p/134382#M29413</guid>
      <dc:creator>rsmits1074</dc:creator>
      <dc:date>2025-06-04T14:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Nfs kerberos encryption types</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Nfs-kerberos-encryption-types/m-p/134406#M29416</link>
      <description>&lt;P&gt;Following Kerberos 5 are supported:&lt;/P&gt;&lt;DIV class="body conbody"&gt;&lt;UL&gt;&lt;LI&gt;Kerberos 5 authentication with integrity checking (krb5i)&lt;P class="p"&gt;Krb5i uses checksums to verify the integrity of each NFS message transferred between client and server. This is useful both for security reasons, for example to ensure that data has not been tampered with, and data integrity reasons, for example to prevent data corruption when using NFS over unreliable networks.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Kerberos 5 authentication with privacy checking (krb5p)&lt;P class="p"&gt;Krb5p uses checksums to encrypt all the traffic between client and the server. This is more secure and also incurs more load.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;128-bit and 256-bit AES encryption&lt;P class="p"&gt;Advanced Encryption Standard (AES) is an encryption algorithm for securing electronic data. Data ONTAP now supports AES with 128-bit keys (AES-128) and AES with 256-bit keys (AES-256) encryption for Kerberos for stronger security.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph"&gt;SVM&lt;/SPAN&gt;-level Kerberos realm configurations&lt;P class="p"&gt;&lt;SPAN class="ph"&gt;SVM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;administrators can now create Kerberos realm configurations at the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;SVM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;level. This means that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;SVM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;administrators no longer have to rely on the cluster administrator for Kerberos realm configuration and can create individual Kerberos realm configurations in a multi-tenancy environment.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV class="related-links"&gt;&lt;DIV class="familylinks"&gt;&lt;DIV class="parentlink"&gt;&lt;STRONG&gt;Parent topic:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="You can use Kerberos to provide strong authentication between SVMs and NFS clients to provide secure NFS communication. Configuring NFS with Kerberos increases the integrity and security of NFS client communications with the storage system." href="http://docs.netapp.com/ontap-9/topic/com.netapp.doc.cdot-famg-nfs/GUID-3ECE9551-A805-460B-86EC-EBCC14422528.html" target="_blank"&gt;Using Kerberos with NFS for strong security&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="parentlink"&gt;Reference&amp;nbsp;&lt;A href="http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-F5F91EE8-7080-4820-9D6D-958E115189D4.html" target="_blank"&gt;http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-F5F91EE8-7080-4820-9D6D-958E115189D4.html&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Sep 2017 04:56:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Nfs-kerberos-encryption-types/m-p/134406#M29416</guid>
      <dc:creator>Sahana</dc:creator>
      <dc:date>2017-09-12T04:56:08Z</dc:date>
    </item>
  </channel>
</rss>

