HTTPS connection and authentication are not supported between swift-proxy and swift-account-server/swift-container-server/swift-object-server.
Bug #1674191 reported by
Yikun Jiang
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Object Storage (swift) |
Confirmed
|
Wishlist
|
Unassigned | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
HTTPS connection and authentication are not supported between swift-proxy and swift-account-
The issue description as following:
All the components of swift-proxy, swift-account-
The base-cvss-score of the issue is 6.3.
Changed in ossa: | |
status: | New → Incomplete |
description: | updated |
To post a comment you must log in.
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.
This seems like a known behavior already documented in the security guide: https:/ /docs.openstack .org/security- guide/object- storage. html#first- thing-to- secure- the-network . Issues around management network are usually triaged as class C1 according to VMT's taxonomy ( https:/ /security. openstack. org/vmt- process. html#incident- report- taxonomy ).