Project

General

Profile

Actions

Bug #23264

open

Server side encryption support for s3 COPY operation

Added by Casey Bodley about 6 years ago. Updated 14 days ago.

Status:
In Progress
Priority:
Normal
Assignee:
Target version:
-
% Done:

0%

Source:
Tags:
sse
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

If the source object of a copy operation is encrypted with SSE-C, we should be requiring the x-amz-copy-source-​server-side​-encryption​-customer-* headers necessary to decrypt it, and then apply the x-amz-server-side​-encryption​-customer-* headers (if given) to re-encrypt the target object.

For SSE-KMS, we should also respect the x-amz-server-side-encryption* headers when writing the target object.


Related issues 2 (0 open2 closed)

Related to rgw - Bug #23232: RGWCopyObj silently corrupts the object that was mulitpart-uploaded in SSE-CResolvedCasey Bodley03/06/2018

Actions
Has duplicate rgw - Bug #45942: [rgw] copy object on bucket with SSE-C returns NotImplementedDuplicate

Actions
Actions

Also available in: Atom PDF