Bug 2107098 - [RHOS17] Radosgw access denied when trying to get object with temp_url using SHA256 digest
Summary: [RHOS17] Radosgw access denied when trying to get object with temp_url using...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tempest
Version: 17.0 (Wallaby)
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: beta
: 17.0
Assignee: Giulio Fidente
QA Contact: Yogev Rabl
URL:
Whiteboard:
Depends On: 2105950
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-07-14 10:57 UTC by Giulio Fidente
Modified: 2022-09-21 12:24 UTC (History)
14 users (show)

Fixed In Version: openstack-tempest-31.1.0-0.20220705220829.56d259d.el9ost
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-09-21 12:24:05 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-17622 0 None None None 2022-07-14 11:04:16 UTC
Red Hat Product Errata RHEA-2022:6543 0 None None None 2022-09-21 12:24:25 UTC

Description Giulio Fidente 2022-07-14 10:57:20 UTC
This bug was initially created as a copy of Bug #2105950

RGW needs support for SHA256 (or other FIPS compliant) algo for tempurl digests [1]

1. https://bugzilla.redhat.com/show_bug.cgi?id=2105950#c14

Comment 6 Yaniv Kaul 2022-07-25 08:15:41 UTC
Moved to VERIFIED, based on:
We got build 0721, FIRST TIME we passed phase 1 & 2, !!!!
We are in the middle of Phase 3.

(From Nathan)

Comment 7 Pavel Sedlák 2022-07-25 09:09:44 UTC
Extra note:

with having tempest switched to sha1 in tempest.conf:
> [object-storage-feature-enabled]
> tempurl_digest_hashlib = sha1
> discoverable_apis = bulk_delete,container_quotas,tempurl,slo,account_quotas,staticweb,tempauth

affected tests are passing now:
> tempest.api.object_storage.test_object_temp_url.ObjectTempUrlTest" name="test_get_object_using_temp_url[id-f91c96d4-1230-4bba-8eb9-84476d18d991]" time="0.044"
> tempest.api.object_storage.test_object_temp_url.ObjectTempUrlTest" name="test_get_object_using_temp_url_key_2[id-671f9583-86bd-4128-a034-be282a68c5d8]" time="0.044"
> tempest.api.object_storage.test_object_temp_url.ObjectTempUrlTest" name="test_get_object_using_temp_url_with_inline_query_parameter[id-9d9cfd90-708b-465d-802c-e4a8090b823d]" time="0.018"
> tempest.api.object_storage.test_object_temp_url.ObjectTempUrlTest" name="test_head_object_using_temp_url[id-249a0111-5ad3-4534-86a7-1993d55f9185]" time="0.028"
> tempest.api.object_storage.test_object_temp_url.ObjectTempUrlTest" name="test_put_object_using_temp_url[id-9b08dade-3571-4152-8a4f-a4f2a873a735]" time="0.069"

Comment 12 errata-xmlrpc 2022-09-21 12:24:05 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Release of components for Red Hat OpenStack Platform 17.0 (Wallaby)), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:6543


Note You need to log in before you can comment on or make changes to this bug.