Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NFS - Disable V2 and V3 #6622

Open
maestro7879 opened this issue Dec 12, 2024 · 1 comment
Open

NFS - Disable V2 and V3 #6622

maestro7879 opened this issue Dec 12, 2024 · 1 comment

Comments

@maestro7879
Copy link

Required Info:

  • AWS ParallelCluster version [e.g. 3.1.1]: 3.11.1

CIS security controls would like to have rpcbind.service and rpcbind.socket disabled/masked. The build-image requires a start of rpcbind which as I understand is only required for NFS2 and 3. Is it possible to not make this a requirement?

Error -
Expected process to exit with [0], but received '1'
Stdout: ---- Begin output of ["/usr/bin/systemctl", "--system", "start", "rpc-statd.service"] ----
Stdout: STDOUT:
Stdout: STDERR: Failed to start rpc-statd.service: Unit rpcbind.socket is masked.
Stdout: ---- End output of ["/usr/bin/systemctl", "--system", "start", "rpc-statd.service"] ----
Stdout: Ran ["/usr/bin/systemctl", "--system", "start", "rpc-statd.service"] returned 1

@himani2411
Copy link
Contributor

Hi @maestro7879

In AWS ParallelCluster we use third party cookbook which is the one which enables/starts the rpcbind service.
However we use NFSv4. I have created a Backlog Item for the request you have made to evaluate if it will affect any feature we have with Storage

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants