- Token leak in FTS/XrootD logs
- FTS increased verbosity of their logs, logs accessible to anyone from CERN
- xrootd based storages (Except EOS) affected
- Redirect step (FTS connected to storage head-node, gets redirected to different URL)
- xrootd puts redirect URL (including the bearer token) into the log
- -> Anyone who has access to the log has access to the token
- Tokens have limited lifetime, though scope might have a storage.modify token which could delete the entire storage
- ATLAS response
- Switched off token support for affected sites
- FTS put restrictions to who can view logs (Only very specific subset of users can)
- DC24
- Should we add these sites or not?
- Nothing todo for Rucio
- February meeting schedule
- Feb 01
- Feb 08
- Feb 15 (DC24)
- Feb 22 (DC24)
- Feb 29