diff --git a/THREAT_MODEL.md b/THREAT_MODEL.md index 69f3b9bef13..7882950d3c4 100644 --- a/THREAT_MODEL.md +++ b/THREAT_MODEL.md @@ -178,9 +178,10 @@ stock install and must be explicitly enabled: gRPC traffic when enabled. - **TDE/KMS** is optional and protects data at rest only for encrypted buckets; it requires a configured KMS, for example via `hadoop.security.key.provider.path`. +- **HTTP authentication (SPNEGO)** is off by default (`ozone.security.http.kerberos.enabled=false`, and each web server's own type, for example `ozone.om.http.auth.type=simple`). With these defaults the web endpoints are not authenticated, and the OM and SCM DB checkpoint endpoints, which serve the metadata DB, are served without an admin check. *(documented — `ozone-default.xml`.)* So a finding that assumes ACLs / block/container tokens / transport encryption / -TDE are active in a default build is `OUT-OF-MODEL: non-default-build` unless the +TDE / HTTP authentication are active in a default build is `OUT-OF-MODEL: non-default-build` unless the operator enabled them (§10); the §10 checklist lists these as required production hardening. (Answers the Q-authz / Q-token / Q-tde default-state and lifetime/rotation mechanism questions.) @@ -294,6 +295,7 @@ Per-boundary input trust (grouped by family): - **Protect service metadata at rest.** The OM, SCM, and Recon RocksDB stores hold critical credential/identity data — set restrictive file permissions and, ideally, encrypt them on disk. *(maintainer — jojochuang, 2026-06-25.)* +- **Enable HTTP authentication (SPNEGO)** for the OM and SCM web servers, or network-isolate their HTTP ports. The DB checkpoint endpoints serve the metadata DB. - **Isolate the KMS** in a separate, firewalled network segment. *(maintainer — jojochuang, 2026-06-25.)* - **Client side:** treat data read from Ozone per your own trust needs; protect diff --git a/hadoop-hdds/common/src/main/resources/ozone-default.xml b/hadoop-hdds/common/src/main/resources/ozone-default.xml index 23e2ac5d950..ea1b226b33e 100644 --- a/hadoop-hdds/common/src/main/resources/ozone-default.xml +++ b/hadoop-hdds/common/src/main/resources/ozone-default.xml @@ -3504,6 +3504,8 @@ OM, SECURITY, KERBEROS simple or kerberos. If kerberos is set, SPNEGO will be used for http authentication. + kerberos takes effect only when ozone.security.http.kerberos.enabled is true. + With simple, requests are not authenticated, so the admin check of the /dbCheckpoint and /v2/dbCheckpoint endpoints is not applied. @@ -3512,6 +3514,8 @@ OM, SECURITY, KERBEROS simple or kerberos. If kerberos is set, SPNEGO will be used for http authentication. + kerberos takes effect only when ozone.security.http.kerberos.enabled is true. + With simple, requests are not authenticated, so the admin check of the /dbCheckpoint endpoint is not applied.