Key Rotation

Ceph 19.2.6, the CephX key rotation, and getting through it without losing sleep

Ceph 19.2.6, the CephX key rotation, and getting through it without losing sleep

17 min read

Ceph 19.2.6 is a security patch. What makes it different from every other Ceph patch you have shipped in the last five years is that the fix for the headline CVE introduces the first new CephX key type in the project’s history, aes256k. That turns “update the packages” into “migrate every credential in the cluster, on every node, for every client, without breaking the ones that are in use right now.”

This post walks through the whole thing: what the four CVEs actually are, how CephX authentication works well enough to understand why the rotation is hard, where the keys live on a Proxmox node, the preflight checks that save you during the upgrade, the Proxmox migration helper step by step, and the specific things that went wrong for people who did not follow the procedure.