Files
Zhengchao An 7b20554056 fix(credentials): fail closed when deriving RPC secret from default credentials (#4402)
The internode RPC HMAC secret is derived from the S3 credential pair via
`derive_rpc_secret` when `RUSTFS_RPC_SECRET` is unset. The derivation uses the
secret key as the HMAC key, so when the default secret key (`rustfsadmin`) is in
effect the derived RPC secret is a fixed, publicly computable value. Any network
peer can then forge valid `x-rustfs-signature` headers and invoke internode RPC
routes (e.g. `read_file_stream`), bypassing S3 IAM entirely.

`normalize_rpc_secret` already rejected the literal default when it was supplied
directly, but `resolve_rpc_secret` still derived a secret from the default
credential pair. Make the derivation path fail closed: refuse to derive while
the default secret key is in effect, forcing operators to set `RUSTFS_RPC_SECRET`
(or a non-default `RUSTFS_SECRET_KEY`). A default access key paired with a
non-default secret key remains safe and is still allowed.

Addresses GHSA-68cw-96m3-h2cf (incomplete-fix follow-up to CVE-2026-45039).
2026-07-08 09:31:25 +08:00
..

RustFS

RustFS Credentials - Credential Management Module

A module for managing credentials within the RustFS distributed object storage system.

CI 📖 Documentation · 🐛 Bug Reports · 💬 Discussions


This module provides a secure and efficient way to handle various types of credentials, such as API keys, access tokens, and cryptographic keys, required for interacting with the RustFS ecosystem and external services.

📖 Overview

RustFS Credentials is a module dedicated to managing credentials for the RustFS distributed object storage system. For the complete RustFS experience, please visit the main RustFS repository

Features

  • Secure storage and retrieval of credentials
  • Support for multiple credential types (API keys, tokens, etc.)
  • Encryption of sensitive credential data
  • Integration with external secret management systems
  • Easy-to-use API for credential management
  • Credential rotation and expiration handling

📚 Documentation

For comprehensive documentation, examples, and usage guides, please visit the main RustFS repository.

📄 License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.