Until recently, integrity measurement support was available only on local file systems. This talk describes the design of a proposed extension of the NFS protocol to support IMA. The discussion will include the design's strengths and limitations, and remaining challenges.
Chuck Lever has been a contributor to the Linux NFS implementation for nearly 20 years, working on such features as IPv6 support and NFS/RDMA. He has also published several NFS-related RFCs.