Project

General

Profile

Actions

Bug #36586

open

ceph-volume /etc/ceph/osd files contains keyring and is worldwide readable.

Added by Mehdi Abaakouk over 5 years ago. Updated over 5 years ago.

Status:
New
Priority:
High
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

ceph-volume simple scan creates files in /etc/ceph/osd worldwide readable.

These files contains keyring of the osd.

Permissions of keyring stuff must be owned and readable by root only.

Actions #1

Updated by Mehdi Abaakouk over 5 years ago

or something like ceph:ceph 400

Actions #2

Updated by Mehdi Abaakouk over 5 years ago

  • Project changed from Ceph to ceph-volume
Actions #3

Updated by Mehdi Abaakouk over 5 years ago

  • Assignee set to Mehdi Abaakouk
Actions #4

Updated by Mehdi Abaakouk over 5 years ago

  • Priority changed from Normal to High
Actions

Also available in: Atom PDF