From 2ce504bb99cf6fb75caaeacc63d6542515870ef0 Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Wed, 27 Feb 2019 00:48:56 -0800 Subject: [PATCH] Updated Security Overview (markdown) --- Security-Overview.md | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/Security-Overview.md b/Security-Overview.md index 719be21..63fa4d6 100644 --- a/Security-Overview.md +++ b/Security-Overview.md @@ -24,13 +24,7 @@ All gRPC operations can optionally be secured via mutual TLS, by customizing the # Securing Volume Servers -There are 2 ways to change volume servers: -1. Administrative operations via gRPC -1. File upload, update, and delete operations. - -To control administrative operations, mutual TLS can be enabled for all gRPC calls. - -To control file upload/update/delete operations, Json Web Token (JWT) is used to authorize access for each file id. +Besides gRPC mentioned above, volume servers can only be changed by file upload, update, and delete operations. Json Web Token (JWT) is used to authorize access for each file id. ## JWT-based access control To enable JWT-based access control,