Re: Rotate lockbox keyring

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


I figured out that I'll need to update the lv tag `ceph.cephx_lockbox_secret`
as well.

-Zhongzhou Cai

On Mon, Feb 6, 2023 at 5:27 PM Zhongzhou Cai <zhongzhoucai@xxxxxxxxxx>

> Hi,
> I'm on Ceph 16.2.10, and I'm trying to rotate the ceph lockbox keyring. I
> used ceph-authtool to create a new keyring, and used `ceph auth import -i
> <new-keyring>` to update the lockbox keyring. I also updated the keyring
> file, which is /var/lib/ceph/osd/ceph-<osd-id>/lockbox.keyring. I tried
> `systemctl restart ceph-volume@lvm-<osd-id>-<osd-fsid>.service`, the
> command succeeded. Then I rebooted the node, ceph-volume failed because the
> lockbox.keyring file was overwritten with the old key, which doesn't match
> the lockbox keyring in `ceph auth get`. Does anyone know where it gets the
> lockbox.keyring during reboot?
> Thanks,
> Zhongzhou Cai
ceph-users mailing list -- ceph-users@xxxxxxx
To unsubscribe send an email to ceph-users-leave@xxxxxxx

[Index of Archives]     [Information on CEPH]     [Linux Filesystem Development]     [Ceph Development]     [Ceph Large]     [Ceph Dev]     [Linux USB Development]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]     [xfs]

  Powered by Linux