[astute] Astute should not log deployment data
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Fuel for OpenStack |
Fix Released
|
High
|
Vladimir Sharshov |
Bug Description
Astute log deployment data event even if log level set to info.
This may be a security issue and we should log this only in debug mode.
https:/
https:/
https:/
https:/
Update:
Rabbit anc cobbler credentials on master node are also exposed
2016-06-03 05:15:05 INFO [19980] Starting with settings
....
:broker_username: naily
:broker_password: 1ISnmaZdSwdsQpQ
:broker_
:broker_queue: naily
:broker_
:broker_exchange: nailgun
2016-06-03 05:31:36 INFO [20002] Run hook ---
type: cobbler_sync
uids:
- master
parameters:
provisioning_
engine:
url: http://
username: cobbler
password: 3z8TaPOVkknB2Z7
master_ip: 10.0.203.2
2016-06-03 15:10:16 INFO [5007] Trying to instantiate cobbler engine:
{"url"=>"http://
"username"
"password"
"master_
Changed in fuel: | |
milestone: | none → 10.0 |
status: | New → Confirmed |
importance: | Undecided → High |
assignee: | nobody → Vladimir Sharshov (vsharshov) |
tags: | added: area-python |
tags: | added: feature-security |
description: | updated |
description: | updated |
(This check performed automatically)
Please, make sure that bug description contains the following sections filled in with the appropriate data related to the bug you are describing:
actual result
version
expected result
steps to reproduce
For more detailed information on the contents of each of the listed sections see https:/ /wiki.openstack .org/wiki/ Fuel/How_ to_contribute# Here_is_ how_you_ file_a_ bug