Security Guide - Chapter 43. Image Creation Process says 'secure' when it means 'verifiable'

Bug #1344309 reported by N Dillon
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openstack-manuals
Fix Released
Medium
Renee

Bug Description

This section is referring to how to validate image integrity. Hardening is mentioned in the sentence before: "Additionally it is assumed that you have a process by which you install and harden operating systems." It would be scary for someone to follow this guide and think that pulling a stock image from a repository was a 'secure' image. The only sections after this sentence are concerning live migrations.

Currently States: "Thus, the following items will provide additional guidance on how to ensure your images are built securely prior to upload."

Recommended Update: "Thus, the following items will provide additional guidance on how to ensure your images are transferred securely into OpenStack."
-----------------------------------
Built: 2014-07-18T11:07:05 00:00
git SHA: 2dc0f54e2f4b1a51cfcf33c90c799d0f1b3a1cb7
URL: http://docs.openstack.org/security-guide/content/security-services-for-instances.html
source File: file:/home/jenkins/workspace/security-doc-tox-doc-publishdocs/security-guide/ch_security-services-for-instances.xml
xml:id: security-services-for-instances

Changed in openstack-manuals:
status: New → Confirmed
importance: Undecided → Medium
tags: added: low-hanging-fruit sec-guide
Renee (renee-rendon)
Changed in openstack-manuals:
assignee: nobody → Renee (renee-rendon)
assignee: Renee (renee-rendon) → nobody
assignee: nobody → Renee (renee-rendon)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to security-doc (master)

Fix proposed to branch: master
Review: https://review.openstack.org/109686

Changed in openstack-manuals:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to security-doc (master)

Reviewed: https://review.openstack.org/109686
Committed: https://git.openstack.org/cgit/openstack/security-doc/commit/?id=183a99e2b11f6f029573742112018ec500a8c5ac
Submitter: Jenkins
Branch: master

commit 183a99e2b11f6f029573742112018ec500a8c5ac
Author: Renee Rendon <email address hidden>
Date: Fri Jul 25 14:02:12 2014 -0500

    Wording change based on bug feedback

    Change-Id: I2f00846d5e4c740823bfe55ea1ea2494bf26f8ab
    Closes-bug: 1344309

Changed in openstack-manuals:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.