Project

General

Profile

Actions

Bug #14950

closed

keyring permisions for mon deamon

Added by Owen Synge about 8 years ago. Updated over 7 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
other
Tags:
Backport:
hammer, infernalis
Regression:
No
Severity:
3 - minor
Reviewed:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

The command:

sudo ceph-mon --cluster ceph --mkfs -i ceph-node3 --keyring /var/lib/ceph/tmp/ceph-ceph-node3.mon.keyring

Writes a new keyring with permissions set to "0644".

If I was administering a ceph cluster I would not let users on to the cluster, but others might. Hence this is a serious security flaw suitable for a CVE.

This bug is present in all released versions of ceph I have tested from master to firefly.

I will send a patch in a few mins to resolve this.


Related issues 2 (0 open2 closed)

Copied to Ceph - Backport #15021: infernalis: keyring permisions for mon deamonRejectedActions
Copied to Ceph - Backport #15022: hammer: keyring permisions for mon deamonResolvedXiaoxi ChenActions
Actions #2

Updated by Nathan Cutler about 8 years ago

Note: the PR containing the above commit is https://github.com/ceph/ceph/pull/7880

Actions #3

Updated by Kefu Chai about 8 years ago

  • Status changed from New to Fix Under Review
  • Assignee set to Owen Synge
Actions #4

Updated by Kefu Chai about 8 years ago

  • Status changed from Fix Under Review to Resolved
Actions #5

Updated by Kefu Chai about 8 years ago

  • Backport set to hammer, infernalis, jewel
Actions #6

Updated by Kefu Chai about 8 years ago

  • Status changed from Resolved to Pending Backport
Actions #7

Updated by Nathan Cutler about 8 years ago

  • Backport changed from hammer, infernalis, jewel to hammer, infernalis
Actions #8

Updated by Nathan Cutler about 8 years ago

  • Copied to Backport #15021: infernalis: keyring permisions for mon deamon added
Actions #9

Updated by Nathan Cutler about 8 years ago

  • Copied to Backport #15022: hammer: keyring permisions for mon deamon added
Actions #10

Updated by Loïc Dachary over 7 years ago

  • Status changed from Pending Backport to Resolved
Actions

Also available in: Atom PDF