Bug 1637529 - [RFE] Avoid requirement to put Keystone secrets (admin token or admin password) in plain text/unencrypted in Ceph Object Gateway configuration
Summary: [RFE] Avoid requirement to put Keystone secrets (admin token or admin passwor...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat
Component: RGW
Version: 3.0
Hardware: x86_64
OS: Unspecified
urgent
urgent
Target Milestone: rc
: 3.2
Assignee: Matt Benjamin (redhat)
QA Contact: Tejas
Bara Ancincova
URL:
Whiteboard:
Depends On:
Blocks: 1629656
TreeView+ depends on / blocked
 
Reported: 2018-10-09 12:33 UTC by Karun Josy
Modified: 2019-01-03 19:02 UTC (History)
12 users (show)

Fixed In Version: RHEL: ceph-12.2.8-32.el7cp Ubuntu: ceph_12.2.8-31redhat1
Doc Type: Bug Fix
Doc Text:
.The Keystone credentials were moved to an external file When using the Keystone identity service to authenticate a Ceph Object Gateway user, the Keystone credentials were set as plain text in the Ceph configuration file. With this update, the Keystone credentials are configured in an external file that only the Ceph user can read.
Clone Of:
Environment:
Last Closed: 2019-01-03 19:02:01 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2019:0020 None None None 2019-01-03 19:02:15 UTC
Ceph Project Bug Tracker 24816 None None None 2018-10-30 02:03:25 UTC

Description Karun Josy 2018-10-09 12:33:15 UTC
Description of problem:

When using Keystone to Authenticate Ceph Object Gateway User,
while configuring civetweb we are giving the rgw_keystone_admin_password as plain text in ceph.conf as mentioned in our doc[1].

The documents says there are  2 ways to  configure civetweb users; as plain text user/password or token based. But Red Hat recommends disabling authentication by admin token in production environments. 
Will it be possible to set up a secure authentication process, avoiding the unencrypted password in the configuration file ceph.conf, like encrypted password? 

[1] https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/2/html-single/using_keystone_to_authenticate_ceph_object_gateway_users/index

Version-Release number of selected component (if applicable):
3.*

How reproducible:
Always

Comment 26 errata-xmlrpc 2019-01-03 19:02:01 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:0020


Note You need to log in before you can comment on or make changes to this bug.