followup
authorJoey Hess <joeyh@joeyh.name>
Wed, 13 Jul 2022 18:53:46 +0000 (14:53 -0400)
committerJoey Hess <joeyh@joeyh.name>
Wed, 13 Jul 2022 18:53:46 +0000 (14:53 -0400)
doc/bugs/fails_to_authenticate_into_S3_for_initremote__63__.mdwn
doc/bugs/fails_to_authenticate_into_S3_for_initremote__63__/comment_1_a7fcd34cf9376e900db832a8010df7d7._comment [new file with mode: 0644]
doc/todo/allow_for_annonymous_AWS_S3_access/comment_1_0723643146ba36131218be090e6d5c73._comment [new file with mode: 0644]

index cb103f74364c1b1d1654295a83edab050873484b..32c025eaa935171467824fa4b8c89cd90b7bb09f 100644 (file)
@@ -26,3 +26,6 @@ what exactly does it want from me for AWS4-HMAC-SHA256 ?  here is how those secr
 $ echo AWS_ACCESS_KEY_ID=$(awk '/^access_key/{print $3}' ~/.s3cfg-dandi-backup) AWS_SECRET_ACCESS_KEY=$(awk '/^secret_key/{print $3}' ~/.s3cfg-dandi-backup) | tr 'a-z0-9' '?-?'
 AWS_ACCESS_KEY_ID=AKIA?GIMZPVVE??Y?NKH AWS_SECRET_ACCESS_KEY=/??U??TV?LH?L???KZJ??RF?G???Y+?S??????LM
 ```
+
+[[!meta author=yoh]]
+[[!tag projects/dandi]]
diff --git a/doc/bugs/fails_to_authenticate_into_S3_for_initremote__63__/comment_1_a7fcd34cf9376e900db832a8010df7d7._comment b/doc/bugs/fails_to_authenticate_into_S3_for_initremote__63__/comment_1_a7fcd34cf9376e900db832a8010df7d7._comment
new file mode 100644 (file)
index 0000000..0096874
--- /dev/null
@@ -0,0 +1,11 @@
+[[!comment format=mdwn
+ username="joey"
+ subject="""comment 1"""
+ date="2022-07-13T17:46:54Z"
+ content="""
+That seems to be Signature Version 4. Try adding this to the initremote: signature=v4
+
+Some AWS regions need V4, others still work with V2, which is what it used
+by default. I have not seen the default US region require V4 before.
+Could be something about your AWS access key that needs v4?
+"""]]
diff --git a/doc/todo/allow_for_annonymous_AWS_S3_access/comment_1_0723643146ba36131218be090e6d5c73._comment b/doc/todo/allow_for_annonymous_AWS_S3_access/comment_1_0723643146ba36131218be090e6d5c73._comment
new file mode 100644 (file)
index 0000000..b0a0b17
--- /dev/null
@@ -0,0 +1,17 @@
+[[!comment format=mdwn
+ username="joey"
+ subject="""comment 1"""
+ date="2022-07-13T18:16:57Z"
+ content="""
+I've checked and the haskell aws library does not currently support this.
+Since the library currently needs a maintainer, I have not filed an issue
+to implement this.
+
+It might be possible to work around it, by using s3SignQuery with a dummy
+credentials, and then modifying the SignedQuery that it returns to remove
+the authentication headers. Or by bypassing s3SignQuery and constructing
+a SignedQuery that is not actually signed.
+
+Do you have a sample bucket that does allow anonymous access, not only
+to individual files, but to listing the content of the bucket?
+"""]]