Re: [CVE] [URGENT] Squid v19.2.6 and Tentacle v20.2.4 released
On Fri, Aug 21, 2026 at 7:40 AM Burkhard Linke <ceph-users@ceph.io> wrote:
Hi,
On 8/20/26 21:35, Patrick Donnelly wrote:
A challenge to that approach is that Proxmox PVE defines external RBD pools at the datacenter level using a single user/key pair. This then becomes the storage pool on each individual node in the proxmox cluster. I believe ceph-csi K8 storage class also defines this once cluster wide. I understand but the only way to change things is to spread the word. If the key is that challenging to rotate, then I would suggest leaving it as aes and push for changes in the product or deployment technology. Rook developers are already aware this should be reworked.
So you expect every user running Proxmox PVE, K8s with ceph csi or Openstack (which is usually more than just a handful of hosts) to figure out how to adopt their deployment? Which is not possible at this time for the mentioned cases.
I'm not sure what you mean. I think the docs are clear that it may not be possible to rotate client keys to the stronger key type due to various technical hurdles. That is okay. The CVE is mitigated by updating the core Ceph daemons.
Most users will probably welcome a more detailed documentation on how to handle key rotation _and_ especially how to manage the client side in this scenario. As was already mentioned before, most of us cannot simply shutdown all virtual machines in Proxmox or Openstack for a key rotation....
https://docs.ceph.com/en/latest/security/CVE-2025-30156/ "Client/kernel upgrades are recommended to support the new key type but not required to resolve the most serious aspects of the security vulnerability." and https://docs.ceph.com/en/latest/rados/configuration/auth-config-ref/index.ht... "If you cannot rotate a particular client key yet, you may prefer to mute the health warning until you can complete upgrading all of the client keys. We expect this to be typical situation for some clusters." How would you like the docs improved? -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D
participants (1)
-
Patrick Donnelly