Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-4006

Disallow MPU on encrypted buckets.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • None
    • 1.0.0
    • None

    Description

      With HDDS-3612 buckets created via ozone are also accessible via S3.
      This has caused a problem when the bucket is encrypted, the keys are not encrypted on disk.

      2 Issues:
      1. On OM, for each part a new encryption info is generated. During complete Multipart upload, the encryption info is not stored in KeyInfo.
      2. On the client, for part upload, the encryption info is silently ignored.

      If we don't throw an error, on an encrypted bucket, key data is not encrypted on disks.
      For 0.6.0 release, we can mark this as not supported, and this will be fixed in next release by HDDS-4005

      Attachments

        Issue Links

          Activity

            People

              bharat Bharat Viswanadham
              bharat Bharat Viswanadham
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: