vault: Information for authentication appear in debug logs

Bug #2058397 reported by Takashi Kajinami
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Barbican
In Progress
Undecided
Takashi Kajinami
castellan
In Progress
Undecided
Takashi Kajinami

Bug Description

The following options of vault key manager are used for authentication with Vault.

root_token_id: This is not actually an id but a token string

approle_role_id and approle_secret_id: approle_role_id and approle_secret_id

However these options currently lack secret=True and appear in debug logs (during start up, when all options are dumped)

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to castellan (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/openstack/castellan/+/913690

Changed in castellan:
status: New → In Progress
Changed in castellan:
assignee: nobody → Takashi Kajinami (kajinamit)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to barbican (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/openstack/barbican/+/913691

Changed in barbican:
status: New → In Progress
Changed in barbican:
assignee: nobody → Takashi Kajinami (kajinamit)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.