From 276da74687827929dfb5ce46eb12547009a4041d Mon Sep 17 00:00:00 2001 From: Ville Ojamo <14869000+bluikko@users.noreply.github.com> Date: Wed, 1 Jul 2026 15:56:01 +0700 Subject: [PATCH] common/options: fix invalid command for STS key generation Config rgw_sts_key expects a 16-character hexadecimal key. The option long_desc has an example with openssl rand -hex 16 which generates 16 hexadecimal bytes that consist of 32 characters rendered in ASCII. Modify the example openssl command to output 8 bytes that matches the required length of 16 characters. Remove a space after a slash. Raised in the doc bugs pad. Signed-off-by: Ville Ojamo --- src/common/options/rgw.yaml.in | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/common/options/rgw.yaml.in b/src/common/options/rgw.yaml.in index 4a5c8abc5fb9..cc6f3b695432 100644 --- a/src/common/options/rgw.yaml.in +++ b/src/common/options/rgw.yaml.in @@ -3796,9 +3796,9 @@ options: type: str level: advanced desc: STS Key - long_desc: Key used for encrypting/ decrypting role session tokens. + long_desc: Key used for encrypting/decrypting role session tokens. This key must consist of 16 hexadecimal characters, which can be - generated by the command 'openssl rand -hex 16'. All radosgw instances + generated by the command 'openssl rand -hex 8'. All radosgw instances in a zone should use the same key. In multisite configurations, all zones in a realm should use the same key. services: -- 2.47.3