Project

General

Profile

Bug #2526

ceph-mon $mon_data_dir/keyring is world readable

Added by Anonymous over 11 years ago. Updated over 11 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
% Done:

0%

Source:
Development
Tags:
Backport:
stable
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Keys to the kingdom, for anyone to grab. ceph-mon --mkfs creates this file, it should enforce the access mode.

ubuntu@inst01:~$ ls l /var/lib/ceph/mon/ceph-inst01/keyring
-rw-r--r-
1 root root 77 Jun 7 20:22 /var/lib/ceph/mon/ceph-inst01/keyring

Associated revisions

Revision 7332e9c7 (diff)
Added by Sage Weil over 11 years ago

mon: use mode 0600 throughout

Fixes: #2526
Signed-off-by: Sage Weil <>

History

#1 Updated by Sage Weil over 11 years ago

  • Status changed from New to Resolved
  • Backport set to stable

Also available in: Atom PDF