All of lore.kernel.org
 help / color / mirror / Atom feed
* CDS blueprint: strong auth for cephfs
@ 2013-11-13 16:05 Dan van der Ster
  2013-11-13 17:45 ` Gregory Farnum
  0 siblings, 1 reply; 11+ messages in thread
From: Dan van der Ster @ 2013-11-13 16:05 UTC (permalink / raw)
  To: ceph-devel@vger.kernel.org
  Cc: Andreas Joachim Peters, andrea.ieri, Arne Wiebalck

Hi all,
This mail is just to let you know that we've prepared a draft
blueprint related to adding strong(er) authn/authz to cephfs:

http://wiki.ceph.com/01Planning/02Blueprints/Firefly/Strong_AuthN_and_AuthZ_for_CephFS

The main goal of the idea is that we'd like to be able to use CephFS
from untrusted clients:
  - the CephX key gives full rw access to pools (e.g. data/metadata)
via rados; we cannot distribute this key to untrusted hosts.
  - root on untrusted clients can forge their uid/gid and rm -rf /cephfs/*.

In the doc we've proposed one way to add authn/authz to the ceph
server side, but perhaps there is a simpler (more feasible in the
short term) solution which would enable us to allow untrusted cephfs
clients.

Best Regards,
Arne & Andreas & Andrea & Dan
CERN IT

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2013-11-15  8:42 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-11-13 16:05 CDS blueprint: strong auth for cephfs Dan van der Ster
2013-11-13 17:45 ` Gregory Farnum
2013-11-14 10:00   ` Dan van der Ster
2013-11-14 15:55     ` Gregory Farnum
2013-11-14 16:21       ` Dan van der Ster
2013-11-14 16:37         ` Gregory Farnum
2013-11-14 20:30           ` Arne Wiebalck
2013-11-14 21:31             ` Gregory Farnum
2013-11-14 20:09     ` Alex Elsayed
2013-11-15  8:42       ` Dan van der Ster
2013-11-14 13:13   ` Arne Wiebalck

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.