[ceph-users] Rgw potential security issue

2015-09-07 Thread sandyxu4999
Hi Cephers,Recently when I did some tests of rgw functions I found that the swift key of a subuser is kept after removing the subuser. As a result, this subuser-swift_key pair can still pass authentication system and get an auth-token (without any permission though). Moreover,

[ceph-users] rgw potential security issue

2015-09-06 Thread Xusangdi
Hi Cephers, Recently when I did some tests of RGW functions I found that the swift key of a subuser is kept after removing the subuser. As a result, this subuser-swift_key pair can still pass authentication system and get an auth-token (without any permission though). Moreover, if we create a s