Please do not enable the service ceph-create-keys by default
Bug #1563330 reported by
Dr. Jens Harbott
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ceph (Ubuntu) |
Opinion
|
Low
|
Unassigned |
Bug Description
This may be useful for an unexperienced user trying to run ceph on a small setup, but for an automated deployment of a ceph cluster, it is pretty annoying that there may be daemons trying to create credentials that will allow access to the whole cluster if only the new machine gets compromised.
Changed in ceph (Ubuntu): | |
status: | New → Fix Committed |
importance: | Undecided → Medium |
To post a comment you must log in.
This bug was fixed in the package ceph - 10.1.0-0ubuntu1
---------------
ceph (10.1.0-0ubuntu1) xenial; urgency=medium
* New upstream release candidate for Ceph Jewel pad.lv/ 1563714 for FFe): rules,librgw* : Add new binary packages for librgw2. systemd- escaping. patch,pybind- flags.patch: Dropped, openssl- linking. patch: Disable build time linking compat. patch: Cherry pick upstream fix for 32 bit lity, resolving FTBFS on armhf/i386. user-group- osd-prestart. patch: Drop --setuser/ --setgroup prestart. sh; they are not supported infinity. patch: Drop systemd limitation of number of
(see http://
- d/control,
- d/p/fix-
included upstream.
- d/p/*: Refresh remaining patches.
- d/control: Add BD on libldap2-dev for rados gateway.
- d/p/disable-
with OpenSSL due to licensing incompatibilities.
- d/*.symbols: Add new symbols for RC.
- d/python-*.install: Correct wildcards for python module install.
- d/p/32bit-
compatibi
* d/rules: Strip rbd-mirror package correctly.
* d/rules: Install upstart and systemd configurations for rbd-mirror.
* d/copyright: Ensure that jerasure and gf-complete are not stripped
from the upstream release tarball.
* d/p/drop-
arguments from call to ceph-osd-
and generate spurious non-fatal warning messages (LP: #1557461).
* d/p/tasksmax-
processes and threads to long running ceph processes; the default
of 512 tasks is way to low for even a modest Ceph cluster
(LP: #1564917).
* d/rules: Ensure that dh_systemd_start does not insert maintainer
script snippets for ceph-mon and ceph-create-keys - service restart
should be handled outside of the packaging as it is under upstart
and for all other systemd unit files installed (LP: #1563330).
-- James Page <email address hidden> Wed, 06 Apr 2016 09:17:59 +0100