Bug 1276252 - Access to clusters and volumes created with authentication
Summary: Access to clusters and volumes created with authentication
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Gluster Storage
Classification: Red Hat Storage
Component: heketi
Version: unspecified
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: ---
Assignee: Luis Pabón
QA Contact: Anush Shetty
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-10-29 09:15 UTC by Anush Shetty
Modified: 2016-11-08 22:25 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-10-29 10:12:40 UTC
Embargoed:


Attachments (Terms of Use)

Description Anush Shetty 2015-10-29 09:15:19 UTC
Description of problem: When jwt authentication is enabled for heketi servers, the clients authenticate themselves with the server to create clusters and volumes. If the server is later restarted without authentication enabled, the clients get access to all the clusters and volumes, including the ones created when authentication was enabled. 


Version-Release number of selected component (if applicable): heketi-1.0.0-1.el7rhgs.x86_64


How reproducible: Always

Comment 2 Luis Pabón 2015-10-29 10:12:40 UTC
Hi Anush,
  That was the intent, and works as designed.  Do you see a problem here?  The idea is that if the administrator removes the authentication, then access will be provided to the rest of the API functions.  This is the same style as OpenStack Swift.


Note You need to log in before you can comment on or make changes to this bug.