Server Message Block (SMB) file systems use authenticated encryption to protect against interception or tampering when data is transmitted between ECS instances and NAS file systems.

Usage notes

  • Operating systems supported by compute nodes
    On the compute nodes, you must use operating systems that support SMB 3.0 or later. The following table lists the operating systems.
    Type Version
    Windows Server
    • Windows Server 2012 R2 Datacenter 64-bit (Chinese version) and later
    • Windows Server 2012 R2 Datacenter 64-bit (English version) and later
    Aliyun Linux Alibaba Linux 4.19.34 and later
    Red Hat Red Hat Enterprise Linux 7.5 64-bit and later
    CentOS CentOS 7.6 64-bit and later
    Ubuntu Ubuntu 18.04 64-bit and later
    Debian Debian 10.2 64-bit and later
    Suse Enterprise Server SUSE Linux Enterprise Server 12 SP2 64-bit and later
    OpenSUSE openSUSE Leap 42.3 64-bit and later
    CoreOS CoreOS 4.19.43 and later
  • Permissions for transport encryption

    Anonymous users are not allowed to use the transport encryption feature. Only Active Directory (AD) users can use this feature after they mount SMB file systems.

  • Performance loss during transmission encryption

    Compared with a file system for which you disable transmission encryption, a file system for which you enable transmission encryption can be accessed with a 10% more delay and 10% less IOPS.

Enable transport encryption

You can enable transport encryption for an SMB file system only if you use the access control list (ACL) for the SMB file system. The following table describes the parameters that you can specify to enable the feature.
Parameter Description
Enable transport encryption Select Yes to enable transport encryption for the SMB file system.
Deny non-encrypted clients Configure the types of compute nodes that can access the SMB file system.
  • Yes: You can mount the SMB file system by using a compute node for which transport encryption is enabled. This means that you can use an AD account to mount the SMB file system on a compute node whose operating system supports transport encryption.

    However, you cannot mount the SMB file system as an anonymous user or by using a compute node that does not support transport encryption.

  • No: You can mount the SMB file system from all types of compute nodes. However, the transport encryption feature can be enabled only when you use an AD account to mount the SMB file system on a compute node whose operating system supports transport encryption.
For more information, see Features.