diff --git a/Security-Overview.md b/Security-Overview.md index 719be21..63fa4d6 100644 --- a/Security-Overview.md +++ b/Security-Overview.md @@ -24,13 +24,7 @@ All gRPC operations can optionally be secured via mutual TLS, by customizing the # Securing Volume Servers -There are 2 ways to change volume servers: -1. Administrative operations via gRPC -1. File upload, update, and delete operations. - -To control administrative operations, mutual TLS can be enabled for all gRPC calls. - -To control file upload/update/delete operations, Json Web Token (JWT) is used to authorize access for each file id. +Besides gRPC mentioned above, volume servers can only be changed by file upload, update, and delete operations. Json Web Token (JWT) is used to authorize access for each file id. ## JWT-based access control To enable JWT-based access control,