Bug 2222831 - GKLM Integration with Ceph Ceph 6.0
Summary: GKLM Integration with Ceph Ceph 6.0
Keywords:
Status: NEW
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat Storage
Component: RGW
Version: 6.0
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
: 7.1
Assignee: Matt Benjamin (redhat)
QA Contact: Madhavi Kasturi
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-14 00:55 UTC by Alexander
Modified: 2023-07-26 06:34 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHCEPH-7008 0 None None None 2023-07-14 00:57:43 UTC

Description Alexander 2023-07-14 00:55:32 UTC
Description of problem: 
Cu is testing on a test environment for test purposes only

GKLM does not work on Ceph
Cu trying to follow upstream documentation
https://docs.ceph.com/en/quincy/radosgw/kmip/


Cu was advised that it is not officially supported. and to use Hashicorp Vault.

https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6/html/object_gateway_guide/security#the_hashicorp_vault

Spoke with lead architect G.G and confirmed that only Hashicorp is supported

Version-Release number of selected component (if applicable): na


How reproducible: 
not reproducible

Steps to Reproduce:
Cu has done the following:

1. Set up GKLM server
2. Followed steps in https://docs.ceph.com/en/quincy/radosgw/kmip/ 
  2a. adjust the ceph.conf
  2b. create a bucket
  2c. cannot set any encryption as there is no Token available from GKLM or certificate directory on GKLM.
3. Then test the following upload: aws --endpoint-url http://xyz s3 cp /plaintext.txt s3://xyzdirectory/xyzencrypted.txt --sse aws:kms --sse-kms-key-id Kxyz



Actual results:

upload failed: when calling the PutObject operation: Failed to retrieve the actual key, kms-keyid: 

Expected results:
File uploaded

Additional info:
Cu wants to know if there are any plans to support GKLM

Let me know if there is any information that I can add here


Note You need to log in before you can comment on or make changes to this bug.