RandomString resource is using default Python RNG
Bug #1745931 reported by
Pavlo Shchelokovskyy
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Heat |
Fix Released
|
Medium
|
Pavlo Shchelokovskyy |
Bug Description
It might be theoretically possible to infer the state of Python RNG in a (long enough running) heat-engine process by creating many OS::Heat:
We should use SystemRandom instead which under the hood uses system's built-in RNG (like /dev/urandom on Linux).
Changed in heat: | |
assignee: | nobody → Pavlo Shchelokovskyy (pshchelo) |
status: | New → In Progress |
Changed in heat: | |
importance: | Undecided → Medium |
milestone: | none → queens-rc1 |
To post a comment you must log in.
Patch is proposed at https:/ /review. openstack. org/#/c/ 536403/