CVE-2020-25717: s3:auth: start with authoritative = 1