Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.8.0.0 Web Administration Guide

Access key management

Access keys are used to sign the requests you send to the S3 protocol.

Access keys consist of two parts, an access key ID and a secret access key. Like a username and password, you must use both the access key ID and secret access key together to authenticate your requests.

You must generate access key ID and secret access key for an authenticated user upon request. When the user makes an S3 request, the access key ID in request is used to look up the secret access key, and then the signing of request is verified. A PAPI interface is provided for generating this pair for each identity and persists the pair to a cluster-wide store. Each request looks up its credentials in this cluster-wide store, with a possible in-memory cache in the S3 protocol head.

To generate the access key ID and secret access key for an authenticated user upon request, the following rules apply:

  • The access key ID can be a 16 to 128-byte string.
  • A secret key of size 28 bytes is randomly generated, and the user cannot set it.
  • You must store the access key ID and secret access key on disk, for high availability.
  • There is a username (1 to 64-byte string) associated with the access key ID.

Users with the Administrator role are only authorized to generate access keys.

Users have only one access key ID. However, users may have at most two secret keys when the old key has an expiry date set.

If an Administrator creates a new secret key for a user and forgets to set the expiry time, the administrator cannot go back and set the expiry time again. The new key is created and the old key is set to expire after 10 minutes, by default.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\