ceph-s3listed
Install: claude install-skill air-gapped/skills
# ceph-s3
Defaults read from `src/common/options/rgw.yaml.in` at v19.2.6 and v20.2.4;
Rook docs at v1.20.7 and master; tracker and ceph-users as cited. Verified
**2026-09-23**.
## 19.2.6 / 20.2.4 RGW security fixes and their fallout
| CVE | What | Fixed |
|---|---|---|
| CVE-2026-54330 | SigV4 did not check that added `x-amz-*` headers on a presigned request were signed | 19.2.6, 20.2.4 |
| CVE-2026-39944 | STS session-token fields (`is_admin`, account type) could be bit-flipped → RGW admin | 19.2.6, 20.2.4 |
| CVE-2025-30156 | CephX (cluster-wide, not RGW-only) — see rook-ceph-best-practices | 19.2.6, 20.2.4 |
The SigV4 fix breaks two things:
1. **Presigned PUTs from some clients** (restic, PHP SDKs) that send an
unsigned `Content-Type` — rejected (tracker 79674).
Workaround: `ceph config set client.rgw rgw_sigv4_insecure true`, until
19.2.7 / 20.2.5.
2. **RGW multisite forwarding** (non-master zone → master, e.g. bucket
create): `403 AccessDenied` even with every cluster patched
(tracker 79698). `rgw_sigv4_insecure` alone does **not** fix it. Set both
`rgw_sigv4_insecure: "true"` and `rgw_s3_client_max_sig_ver: "2"` in every
zone **before** upgrading. Under Rook, put them in the CephObjectStore
`gateway` config or `rook-config-override`.
Both workarounds re-open CVE-2026-54330: scope them to the affected
clients/zones and revert (`"false"` / `"-1"`) once everything runs a fixed
release.
## AWS SDK checksums
AWS SDKs released from early 2025 s