Project

General

Profile

Actions

Bug #14950

closed

keyring permisions for mon deamon

Added by Owen Synge about 8 years ago. Updated over 7 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
other
Tags:
Backport:
hammer, infernalis
Regression:
No
Severity:
3 - minor
Reviewed:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

The command:

sudo ceph-mon --cluster ceph --mkfs -i ceph-node3 --keyring /var/lib/ceph/tmp/ceph-ceph-node3.mon.keyring

Writes a new keyring with permissions set to "0644".

If I was administering a ceph cluster I would not let users on to the cluster, but others might. Hence this is a serious security flaw suitable for a CVE.

This bug is present in all released versions of ceph I have tested from master to firefly.

I will send a patch in a few mins to resolve this.


Related issues 2 (0 open2 closed)

Copied to Ceph - Backport #15021: infernalis: keyring permisions for mon deamonRejectedActions
Copied to Ceph - Backport #15022: hammer: keyring permisions for mon deamonResolvedXiaoxi ChenActions
Actions

Also available in: Atom PDF