Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
This project is now read‑only. Starting Monday, February 2, please use https://ibm-ceph.atlassian.net/ for all bug tracking management.

Bug 2406973

Summary: [NFS-Ganesha][TLS-Support]: Unable to enable TLS or mTLS without manually adding sectype as "sys" to export block
Product: [Red Hat Storage] Red Hat Ceph Storage Reporter: Manish Singh <manising>
Component: NFS-GaneshaAssignee: Deeraj Patil <deepatil>
NFS-Ganesha sub component: Ceph QA Contact: Manish Singh <manising>
Status: CLOSED ERRATA Docs Contact:
Severity: high    
Priority: unspecified CC: jcaratza, kkeithle, tserlin
Version: 9.0   
Target Milestone: ---   
Target Release: 9.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ceph-20.1.0-88; nfs-ganesha-7.0-0.6.6.el9cp Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-01-29 07:02:49 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2413723    

Description Manish Singh 2025-10-29 05:21:58 UTC
Description of problem:
- Unable to enable TLS or mTLS without manually adding sectype as "sys" to export block

Version-Release number of selected component (if applicable):

[ceph: root@ceph-manish-test-tls-jg6njc-node1-installer /]# ceph --version
ceph version 20.1.0-57.el10cp (6531555b1cbd8e783457956b3cb2e2cdea1e45c8) tentacle (rc)

[ceph: root@ceph-manish-test-tls-jg6njc-node1-installer /]# rpm -qa |grep nfs
libnfsidmap-2.8.2-3.el10.x86_64
nfs-utils-2.8.2-3.el10.x86_64
nfs-ganesha-selinux-7.0-0.6.3.el10cp.noarch
nfs-ganesha-7.0-0.6.3.el10cp.x86_64
nfs-ganesha-ceph-7.0-0.6.3.el10cp.x86_64
nfs-ganesha-rados-grace-7.0-0.6.3.el10cp.x86_64
nfs-ganesha-rados-urls-7.0-0.6.3.el10cp.x86_64
nfs-ganesha-rgw-7.0-0.6.3.el10cp.x86_64
nfs-ganesha-utils-7.0-0.6.3.el10cp.x86_64

How reproducible:
100%

Steps to Reproduce:
1. Create a nfs cluster
2. Create cephfs vol, subvolume group and subvolume.
3. Create export with --sectype sys
4. Generate server certs, client certs as guided for TLS setup.
5. TLS does not get enabled.
6. Modify the export block and append sectype as sys along with TLS, it starts working

Actual results:
TLS does not get enabled without modifying sectype.

Expected results:
TLS should get enabled without sys too

Comment 9 errata-xmlrpc 2026-01-29 07:02:49 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Red Hat Ceph Storage 9.0 Security and Enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2026:1536