Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion THREAT_MODEL.md
Original file line number Diff line number Diff line change
Expand Up @@ -178,9 +178,10 @@ stock install and must be explicitly enabled:
gRPC traffic when enabled.
- **TDE/KMS** is optional and protects data at rest only for encrypted buckets;
it requires a configured KMS, for example via `hadoop.security.key.provider.path`.
- **HTTP authentication (SPNEGO)** is off by default (`ozone.security.http.kerberos.enabled=false`, and each web server's own type, for example `ozone.om.http.auth.type=simple`). With these defaults the web endpoints are not authenticated, and the OM and SCM DB checkpoint endpoints, which serve the metadata DB, are served without an admin check. *(documented — `ozone-default.xml`.)*

So a finding that assumes ACLs / block/container tokens / transport encryption /
TDE are active in a default build is `OUT-OF-MODEL: non-default-build` unless the
TDE / HTTP authentication are active in a default build is `OUT-OF-MODEL: non-default-build` unless the
operator enabled them (§10); the §10 checklist lists these as required
production hardening. (Answers the Q-authz / Q-token / Q-tde default-state and
lifetime/rotation mechanism questions.)
Expand Down Expand Up @@ -294,6 +295,7 @@ Per-boundary input trust (grouped by family):
- **Protect service metadata at rest.** The OM, SCM, and Recon RocksDB stores
hold critical credential/identity data — set restrictive file permissions and,
ideally, encrypt them on disk. *(maintainer — jojochuang, 2026-06-25.)*
- **Enable HTTP authentication (SPNEGO)** for the OM and SCM web servers, or network-isolate their HTTP ports. The DB checkpoint endpoints serve the metadata DB.
- **Isolate the KMS** in a separate, firewalled network segment. *(maintainer —
jojochuang, 2026-06-25.)*
- **Client side:** treat data read from Ozone per your own trust needs; protect
Expand Down
4 changes: 4 additions & 0 deletions hadoop-hdds/common/src/main/resources/ozone-default.xml
Original file line number Diff line number Diff line change
Expand Up @@ -3504,6 +3504,8 @@
<tag>OM, SECURITY, KERBEROS</tag>
<description> simple or kerberos. If kerberos is set, SPNEGO
will be used for http authentication.
kerberos takes effect only when ozone.security.http.kerberos.enabled is true.
With simple, requests are not authenticated, so the admin check of the /dbCheckpoint and /v2/dbCheckpoint endpoints is not applied.
</description>
</property>
<property>
Expand All @@ -3512,6 +3514,8 @@
<tag>OM, SECURITY, KERBEROS</tag>
<description> simple or kerberos. If kerberos is set, SPNEGO
will be used for http authentication.
kerberos takes effect only when ozone.security.http.kerberos.enabled is true.
With simple, requests are not authenticated, so the admin check of the /dbCheckpoint endpoint is not applied.
</description>
</property>
<property>
Expand Down
Loading