Hello Patrick, Patrick Donnelly <pdonnell@redhat.com> writes:
[ kvm/qemu situation ] Again, rotating the client keys is not necessary to address the main vulnerabilities associated with the CVE. You may mute the AUTH_INSECURE_CLIENT_KEY_TYPE warning on an extended basis or
On Fri, Aug 21, 2026 at 10:08 AM Nico Schottelius <ceph-users@ceph.io> wrote: permanently if it cannot be resolved for the forseeable future.
I think that is probably the most important information and I'm sorry if I've overread it before. Just one question: what is the security and maintenance impact of not changing the key type for let's say the next 5 years or so? If there is a muted warning that can be disabled and also if ceph continues to support the old key types, that will solve the maintenance issue for the next years. However there was a good reason to add a new key type to address the vulnerability - and my question is, what type of attacks is the cluster still vulnerable against when continuing to use old keys? Wouldn't it imply that attackers with access to the ceph network can still corrupt data written by clients? BR, Nico -- Sustainable and modern Infrastructures by ungleich.ch