Ceph uses Pybind in a way which does not implement proper certificate checking. This impacts confidentiality and integrity, as an attacker may exploit an unset SSL context to allow the use of any certificate.