Project

General

Profile

Bug #14950

keyring permisions for mon deamon

Added by Owen Synge almost 3 years ago. Updated over 2 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
-
Target version:
-
Start date:
03/02/2016
Due date:
% Done:

0%

Estimated time:
1.00 h
Source:
other
Tags:
Backport:
hammer, infernalis
Regression:
No
Severity:
3 - minor
Reviewed:
ceph-qa-suite:
Pull request ID:

Description

The command:

sudo ceph-mon --cluster ceph --mkfs -i ceph-node3 --keyring /var/lib/ceph/tmp/ceph-ceph-node3.mon.keyring

Writes a new keyring with permissions set to "0644".

If I was administering a ceph cluster I would not let users on to the cluster, but others might. Hence this is a serious security flaw suitable for a CVE.

This bug is present in all released versions of ceph I have tested from master to firefly.

I will send a patch in a few mins to resolve this.


Related issues

Copied to Ceph - Backport #15021: infernalis: keyring permisions for mon deamon Rejected
Copied to Ceph - Backport #15022: hammer: keyring permisions for mon deamon Resolved

Associated revisions

Revision c2f91a8c (diff)
Added by Owen Synge almost 3 years ago

keyring permissions for mon daemon

The command:

sudo ceph-mon --cluster ceph --mkfs -i $NODE_NAME --keyring $PATH_MON_KEYRING

Writes a new keyring with permissions set to "0644".

Fixes: #14950
Signed-off-by: Owen Synge

Revision d4cf1904 (diff)
Added by Owen Synge almost 3 years ago

keyring permissions for mon daemon

The command:

sudo ceph-mon --cluster ceph --mkfs -i $NODE_NAME --keyring $PATH_MON_KEYRING

Writes a new keyring with permissions set to "0644".

Fixes: #14950
Signed-off-by: Owen Synge
(cherry picked from commit c2f91a8ce46974a72b960b7cb25af3d089fbb80d)

History

#2 Updated by Nathan Cutler almost 3 years ago

Note: the PR containing the above commit is https://github.com/ceph/ceph/pull/7880

#3 Updated by Kefu Chai almost 3 years ago

  • Status changed from New to Need Review
  • Assignee set to Owen Synge

#4 Updated by Kefu Chai almost 3 years ago

  • Status changed from Need Review to Resolved

#5 Updated by Kefu Chai almost 3 years ago

  • Backport set to hammer, infernalis, jewel

#6 Updated by Kefu Chai almost 3 years ago

  • Status changed from Resolved to Pending Backport

#7 Updated by Nathan Cutler almost 3 years ago

  • Backport changed from hammer, infernalis, jewel to hammer, infernalis

#8 Updated by Nathan Cutler almost 3 years ago

  • Copied to Backport #15021: infernalis: keyring permisions for mon deamon added

#9 Updated by Nathan Cutler almost 3 years ago

  • Copied to Backport #15022: hammer: keyring permisions for mon deamon added

#10 Updated by Loic Dachary over 2 years ago

  • Status changed from Pending Backport to Resolved

Also available in: Atom PDF