Bug 2299642
Summary: | [CEE] CORS ACL's prevents access to buckets with presigned PUT URI's | |||
---|---|---|---|---|
Product: | [Red Hat Storage] Red Hat Ceph Storage | Reporter: | Michaela Lang <milang> | |
Component: | RGW | Assignee: | Matt Benjamin (redhat) <mbenjamin> | |
Status: | CLOSED ERRATA | QA Contact: | Hemanth Sai <hmaheswa> | |
Severity: | urgent | Docs Contact: | ||
Priority: | unspecified | |||
Version: | 7.1 | CC: | akraj, bkunal, ceph-eng-bugs, cephqe-warriors, ckulal, csharpe, hmaheswa, mbenjamin, mcaldeir, tserlin | |
Target Milestone: | --- | |||
Target Release: | 8.0 | |||
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | ceph-19.1.0-2.el9cp | Doc Type: | Bug Fix | |
Doc Text: |
.Pre-signed URLs are now accepted with Keystone EC2 authentication
Previously, a properly constructed pre-signed HTTP PUT URLs failed unexpectedly, with a `403/Access Denied` error. This happened because of a change in processing of HTTP OPTIONS requests containing CORS changed the implied AWSv4 request signature calculation for some pre-signed URLs when authentication was through Keystone EC2 (Swift S3 emulation).
With this fix, a new workflow for CORS HTTP OPTIONS is introduced for the Keystone EC2 case and pre-signed URLs no longer unexpectedly fail.
|
Story Points: | --- | |
Clone Of: | ||||
: | 2302281 (view as bug list) | Environment: | ||
Last Closed: | 2024-11-25 09:03:40 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 2302281, 2317218 |
Description
Michaela Lang
2024-07-24 07:21:32 UTC
Please see KCS Article #7084669, (https://access.redhat.com/solutions/7084669) regarding this issue. BR Manny Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Red Hat Ceph Storage 8.0 security, bug fix, and enhancement updates), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2024:10216 |