222 lines · plain
1# SPDX-License-Identifier: GPL-2.0-only2config CIFS3 tristate "SMB3 and CIFS support (advanced network filesystem)"4 depends on INET5 select NETFS_SUPPORT6 select NLS7 select NLS_UCS2_UTILS8 select CRYPTO9 select CRYPTO_MD510 select CRYPTO_SHA25611 select CRYPTO_SHA51212 select CRYPTO_CMAC13 select CRYPTO_HMAC14 select CRYPTO_AEAD215 select CRYPTO_CCM16 select CRYPTO_GCM17 select CRYPTO_ECB18 select CRYPTO_AES19 select KEYS20 select DNS_RESOLVER21 select ASN122 select OID_REGISTRY23 select NETFS_SUPPORT24 help25 This is the client VFS module for the SMB3 family of network file26 protocols (including the most recent, most secure dialect SMB3.1.1).27 This module also includes support for earlier dialects such as28 SMB2.1, SMB2 and even the old Common Internet File System (CIFS)29 protocol. CIFS was the successor to the original network filesystem30 protocol, Server Message Block (SMB ie SMB1), the native file sharing31 mechanism for most early PC operating systems.32 33 The SMB3.1.1 protocol is supported by most modern operating systems34 and NAS appliances (e.g. Samba, Windows 11, Windows Server 2022,35 MacOS) and even in the cloud (e.g. Microsoft Azure) and also by the36 Linux kernel server, ksmbd. Support for the older CIFS protocol was37 included in Windows NT4, 2000 and XP (and later). Use of dialects38 older than SMB2.1 is often discouraged on public networks.39 This module also provides limited support for OS/2 and Windows ME40 and similar very old servers.41 42 This module provides an advanced network file system client for43 mounting to SMB3 (and CIFS) compliant servers. It includes support44 for DFS (hierarchical name space), secure per-user session45 establishment via Kerberos or NTLMv2, RDMA (smbdirect), advanced46 security features, per-share encryption, packet-signing, snapshots,47 directory leases, safe distributed caching (leases), multichannel,48 Unicode and other internationalization improvements.49 50 In general, the default dialects, SMB3 and later, enable better51 performance, security and features, than would be possible with CIFS.52 53 If you need to mount to Samba, Azure, ksmbd, Macs or Windows from this54 machine, say Y.55 56config CIFS_STATS257 bool "Extended statistics"58 depends on CIFS59 default y60 help61 Enabling this option will allow more detailed statistics on SMB62 request timing to be displayed in /proc/fs/cifs/DebugData and also63 allow optional logging of slow responses to dmesg (depending on the64 value of /proc/fs/cifs/cifsFYI). See Documentation/admin-guide/cifs/usage.rst65 for more details. These additional statistics may have a minor effect66 on performance and memory utilization.67 68 If unsure, say Y.69 70config CIFS_ALLOW_INSECURE_LEGACY71 bool "Support legacy servers which use less secure dialects"72 depends on CIFS73 default y74 help75 Modern dialects, SMB2.1 and later (including SMB3 and 3.1.1), have76 additional security features, including protection against77 man-in-the-middle attacks and stronger crypto hashes, so the use78 of legacy dialects (SMB1/CIFS and SMB2.0) is discouraged.79 80 Disabling this option prevents users from using vers=1.0 or vers=2.081 on mounts with cifs.ko82 83 If unsure, say Y.84 85config CIFS_UPCALL86 bool "Kerberos/SPNEGO advanced session setup"87 depends on CIFS88 help89 Enables an upcall mechanism for CIFS which accesses userspace helper90 utilities to provide SPNEGO packaged (RFC 4178) Kerberos tickets91 which are needed to mount to certain secure servers (for which more92 secure Kerberos authentication is required). If unsure, say Y.93 94config CIFS_XATTR95 bool "CIFS extended attributes"96 depends on CIFS97 help98 Extended attributes are name:value pairs associated with inodes by99 the kernel or by users (see the attr(5) manual page for details).100 CIFS maps the name of extended attributes beginning with the user101 namespace prefix to SMB/CIFS EAs. EAs are stored on Windows102 servers without the user namespace prefix, but their names are103 seen by Linux cifs clients prefaced by the user namespace prefix.104 The system namespace (used by some filesystems to store ACLs) is105 not supported at this time.106 107 If unsure, say Y.108 109config CIFS_POSIX110 bool "CIFS POSIX Extensions"111 depends on CIFS && CIFS_ALLOW_INSECURE_LEGACY && CIFS_XATTR112 help113 Enabling this option will cause the cifs client to attempt to114 negotiate a feature of the older cifs dialect with servers, such as115 Samba 3.0.5 or later, that optionally can handle more POSIX like116 (rather than Windows like) file behavior. It also enables support117 for POSIX ACLs (getfacl and setfacl) to servers (such as Samba 3.10118 and later) which can negotiate CIFS POSIX ACL support. This config119 option is not needed when mounting with SMB3.1.1. If unsure, say N.120 121config CIFS_DEBUG122 bool "Enable CIFS debugging routines"123 default y124 depends on CIFS125 help126 Enabling this option adds helpful debugging messages to127 the cifs code which increases the size of the cifs module.128 If unsure, say Y.129 130config CIFS_DEBUG2131 bool "Enable additional CIFS debugging routines"132 depends on CIFS_DEBUG133 help134 Enabling this option adds a few more debugging routines135 to the cifs code which slightly increases the size of136 the cifs module and can cause additional logging of debug137 messages in some error paths, slowing performance. This138 option can be turned off unless you are debugging139 cifs problems. If unsure, say N.140 141config CIFS_DEBUG_DUMP_KEYS142 bool "Dump encryption keys for offline decryption (Unsafe)"143 depends on CIFS_DEBUG144 help145 Enabling this will dump the encryption and decryption keys146 used to communicate on an encrypted share connection on the147 console. This allows Wireshark to decrypt and dissect148 encrypted network captures. Enable this carefully.149 If unsure, say N.150 151config CIFS_DFS_UPCALL152 bool "DFS feature support"153 depends on CIFS154 help155 Distributed File System (DFS) support is used to access shares156 transparently in an enterprise name space, even if the share157 moves to a different server. This feature also enables158 an upcall mechanism for CIFS which contacts userspace helper159 utilities to provide server name resolution (host names to160 IP addresses) which is needed in order to reconnect to161 servers if their addresses change or for implicit mounts of162 DFS junction points. If unsure, say Y.163 164config CIFS_SWN_UPCALL165 bool "SWN feature support"166 depends on CIFS167 help168 The Service Witness Protocol (SWN) is used to get notifications169 from a highly available server of resource state changes. This170 feature enables an upcall mechanism for CIFS which contacts a171 userspace daemon to establish the DCE/RPC connection to retrieve172 the cluster available interfaces and resource change notifications.173 If unsure, say Y.174 175config CIFS_NFSD_EXPORT176 bool "Allow nfsd to export CIFS file system"177 depends on CIFS && BROKEN178 help179 Allows NFS server to export a CIFS mounted share (nfsd over cifs)180 181if CIFS182 183config CIFS_SMB_DIRECT184 bool "SMB Direct support"185 depends on CIFS=m && INFINIBAND && INFINIBAND_ADDR_TRANS || CIFS=y && INFINIBAND=y && INFINIBAND_ADDR_TRANS=y186 help187 Enables SMB Direct support for SMB 3.0, 3.02 and 3.1.1.188 SMB Direct allows transferring SMB packets over RDMA. If unsure,189 say Y.190 191config CIFS_FSCACHE192 bool "Provide CIFS client caching support"193 depends on CIFS=m && FSCACHE || CIFS=y && FSCACHE=y194 help195 Makes CIFS FS-Cache capable. Say Y here if you want your CIFS data196 to be cached locally on disk through the general filesystem cache197 manager. If unsure, say N.198 199config CIFS_ROOT200 bool "SMB root file system (Experimental)"201 depends on CIFS=y && IP_PNP202 help203 Enables root file system support over SMB protocol.204 205 Most people say N here.206 207config CIFS_COMPRESSION208 bool "SMB message compression (Experimental)"209 depends on CIFS210 default n211 help212 Enables over-the-wire message compression for SMB 3.1.1213 mounts when negotiated with the server.214 215 Only write requests with data size >= PAGE_SIZE will be216 compressed to avoid wasting resources.217 218 Say Y here if you want SMB traffic to be compressed.219 If unsure, say N.220 221endif222