Rotation key after upgrade to 20.2.4
Hi everyone So today I upgrade (one of) my ceph cluster (cephadm), and indeed after upgrading some time all osd come back to life and all osd key seem to be in aes256k But still with ceph health detail I've got [WRN] AUTH_INSECURE_ROTATING_SERVICE_KEY_TYPE: 4 rotating auth service keys using insecure key types rotating service keys for mon using insecure key type: aes rotating service keys for mds using insecure key type: aes rotating service keys for osd using insecure key type: aes rotating service keys for mgr using insecure key type: aes When I look in the documentation https://docs.ceph.com/en/latest/rados/configuration/auth-config-ref/#cephx-u... section 3 it seem I had to copy the keyring directly to the nodes of my cluster who run those service, but inside /var/lib/ceph/CEPHID/* I didn't find any keyring file related to mon/mds/osd/mgr with aes key. So I'm a little confuse...in the documentation it's say in a note: The mon. historically has not been managed by the Monitor auth database; it exists soley in each Monitor’s keyring inside its data directory. This suggested rotation procedure now puts the authoritative copy in the auth database alongside other keys. The Monitor keyring persists as a fallback or emergency key. so where are those rotation key ? Regards -- Albert SHIH 🦫 🐸 France Heure locale/Local time: jeu. 27 août 2026 11:50:08 CEST
participants (1)
-
Albert Shih