efs-utils.conf 1.38 KB
Newer Older
Max Beckett's avatar
Max Beckett committed
1
2
3
4
5
6
7
8
9
10
11
12
#
# Copyright 2017-2018 Amazon.com, Inc. and its affiliates. All Rights Reserved.
#
# Licensed under the MIT License. See the LICENSE accompanying this file
# for the specific language governing permissions and limitations under
# the License.
#

[DEFAULT]
logging_level = INFO
logging_max_bytes = 1048576
logging_file_count = 10
13
# mode for /var/run/efs and subdirectories in octal
14
state_file_dir_mode = 750
Max Beckett's avatar
Max Beckett committed
15
16

[mount]
17
18
dns_name_format = {fs_id}.efs.{region}.{dns_name_suffix}
dns_name_suffix = amazonaws.com
Max Beckett's avatar
Max Beckett committed
19
stunnel_debug_enabled = false
20
stunnel_cafile = /etc/amazon/efs/efs-utils.crt
Max Beckett's avatar
Max Beckett committed
21

Ian Patel's avatar
Ian Patel committed
22
23
# Validate the certificate hostname on mount. This option is not supported by certain stunnel versions.
stunnel_check_cert_hostname = true
Max Beckett's avatar
Max Beckett committed
24

Ian Patel's avatar
Ian Patel committed
25
# Use OCSP to check certificate validity. This option is not supported by certain stunnel versions.
26
stunnel_check_cert_validity = false
Max Beckett's avatar
Max Beckett committed
27
28
29
30
31

# Define the port range that the TLS tunnel will choose from
port_range_lower_bound = 20049
port_range_upper_bound = 20449

32
33
34
35
36
37
38
39
40
41
42
43
[mount.cn-north-1]
dns_name_suffix = amazonaws.com.cn

[mount.cn-northwest-1]
dns_name_suffix = amazonaws.com.cn

[mount.us-iso-east-1]
dns_name_suffix = c2s.ic.gov

[mount.us-isob-east-1]
dns_name_suffix = sc2s.sgov.gov

Max Beckett's avatar
Max Beckett committed
44
45
46
47
[mount-watchdog]
enabled = true
poll_interval_sec = 1
unmount_grace_period_sec = 30
48
49
50

# Set client auth/access point certificate renewal rate. Minimum value is 1 minute.
tls_cert_renewal_interval_min = 60