{"abstract": "   This document is part of the set of documents intended to update the\n   description of NFSv4 Minor Version One as part of the rfc5661bis\n   respecification effort for NFSv4.1.  It describes the structure and\n   function of NFsv4 Access Control Lists within all existing minor\n   versions of NFSv4.\n\n   It describes the structure of NFSv4 ACLs and their role in the NFSv4\n   security architecture.  While the focus of this document is on the\n   role of ACLs in providing a more flexible approach to file access\n   authorization than is made available by the POSIX-derived\n   authorization-related attributes, the potential provision of other\n   security-related functionality is covered as well.\n\n   [Consensus Needed (Item #117a)]: Because of the failure of previous\n   specifications to provide a satisfactory approach to either of the\n   two ACL models for which support was originally intended, this\n   document clarifies the status of draft-POSIX ACLs, with the\n   expectation that support for these might be provided via a later\n   extension.  In addition, this document will include some small\n   protocol extensions to correct protocol defects, as provided for in\n   RFC8178.\n\n   [Consensus Needed (Item #117a)]: In this document, the relationship\n   among the multiple ACL models for which support was intended has\n   changed.  A core set of functionality, shared in large part with that\n   derived from a subset of the functionality provided by the now-\n   withdrawn draft-POSIX ACLs is presented as the conceptual base of the\n   feature set.  Additional sets of features used to provide the\n   functionality within the NFSv4 ACL model and the full draft-POSIX ACL\n   model are considered as OPTIONAL extensions to that core, with the\n   latter not yet present in NFsv4.1.\n\n   [RFC Editor: please remove this parapgraph and the following\n   paragraph prior to publishing this document as an RFC].\n\n   The current version of the document is intended, in large part, to\n   result in working group discussion regarding repairing problems with\n   previous specifications of ACL-related features and to enable work to\n   provide a greater degree of interoperability than has been available\n   heretofore.  The drafts provide a framework for addressing these\n   issues and obtaining working group consensus regarding changes that\n   will be necesasary before publication of RFCTBD10.\n\n   When the resulting document is eventually published as an RFC, it\n   will supersede the descriptions of ACL structure and semantics\n   appearing in existing minor version specification documents for\n   NFSv4.0 and NFSv4.1, thereby updating RFC7530 and RFC8881.\n", "ad": null, "expires": "2025-11-25T15:58:34Z", "external_url": "", "group": "/api/v1/group/group/1152/", "id": 133783, "intended_std_level": null, "keywords": "[]", "name": "draft-dnoveck-nfsv4-acls", "note": "", "notify": "", "pages": 181, "resource_uri": "/api/v1/doc/document/draft-dnoveck-nfsv4-acls/", "rev": "07", "rfc": null, "rfc_number": null, "shepherd": null, "states": ["/api/v1/doc/state/4/", "/api/v1/doc/state/150/", "/api/v1/doc/state/36/"], "std_level": null, "stream": "/api/v1/name/streamname/ietf/", "submissions": ["/api/v1/submit/submission/152282/", "/api/v1/submit/submission/140553/", "/api/v1/submit/submission/142195/", "/api/v1/submit/submission/143144/", "/api/v1/submit/submission/143172/", "/api/v1/submit/submission/143334/", "/api/v1/submit/submission/145081/", "/api/v1/submit/submission/149452/"], "tags": [], "time": "2025-11-26T07:09:00Z", "title": "ACLs within the NFSv4 Protocols", "type": "/api/v1/name/doctypename/draft/", "uploaded_filename": "", "words": null}