On Fri, Aug 21, 2026 at 10:49 AM Nico Schottelius <nico.schottelius@ungleich.ch> wrote:
Just one question: what is the security and maintenance impact of not changing the key type for let's say the next 5 years or so?
There is a non-zero chance an adversary on the network could figure out the AES128 key. But, if you have an adversary sniffing your Ceph cluster network, you have larger problems.
If there is a muted warning that can be disabled and also if ceph continues to support the old key types, that will solve the maintenance issue for the next years.
At this time, we have no plans to deprecate the aes key type. It would needlessly break compatibility with legacy clients/kernels.
However there was a good reason to add a new key type to address the vulnerability - and my question is, what type of attacks is the cluster still vulnerable against when continuing to use old keys? Wouldn't it imply that attackers with access to the ceph network can still corrupt data written by clients?
There are no known practical attacks on the cluster where only client keys use the "aes" key type. -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D