Re: Insecure keys allowed (aes)
Hello, On Tue, Aug 25, 2026 at 8:32 AM GLE, Vivien <ceph-users@ceph.io> wrote:
Hi,
I just upgrade (from tentacle 20.2.1 to 20.2.4) and rolled CephX keys for a Cephadm cluster but there is still an error concerning the use of insecure keys
#ceph config get mon mon_auth_allow_insecure_key false
#ceph health detail
HEALTH_WARN Monitors are configured to allow auth using insecure key types [WRN] AUTH_INSECURE_KEYS_ALLOWED: Monitors are configured to allow auth using insecure key types insecure cipher aes allowed for auth
Didn't found any keys named like this in the ceph configuration but in the ceph mon dump
Please read the documentation: https://docs.ceph.com/en/latest/rados/operations/health-checks/#auth-insecur... -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D
oops thanks for the fast answer didn't see this part ________________________________ De : Patrick Donnelly <pdonnell@redhat.com> Envoyé : mardi 25 août 2026 14:35:25 À : GLE, Vivien Cc : ceph-users@ceph.io Objet : Re: [ceph-users] Insecure keys allowed (aes) Hello, On Tue, Aug 25, 2026 at 8:32 AM GLE, Vivien <ceph-users@ceph.io> wrote:
Hi,
I just upgrade (from tentacle 20.2.1 to 20.2.4) and rolled CephX keys for a Cephadm cluster but there is still an error concerning the use of insecure keys
#ceph config get mon mon_auth_allow_insecure_key false
#ceph health detail
HEALTH_WARN Monitors are configured to allow auth using insecure key types [WRN] AUTH_INSECURE_KEYS_ALLOWED: Monitors are configured to allow auth using insecure key types insecure cipher aes allowed for auth
Didn't found any keys named like this in the ceph configuration but in the ceph mon dump
Please read the documentation: https://docs.ceph.com/en/latest/rados/operations/health-checks/#auth-insecur... -- Patrick Donnelly, Ph.D. He / Him / His Red Hat Partner Engineer IBM, Inc. GPG: 19F28A586F808C2402351B93C3301A3E258DD79D
participants (2)
-
GLE, Vivien
-
Patrick Donnelly