2015-12-10 09:23:05 |
fujioka yuuichi |
bug |
|
|
added bug |
2015-12-10 09:30:03 |
fujioka yuuichi |
description |
In liberty, a lbaasv2-agent is logging the key that is on barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue. |
In liberty, a lbaasv2-agent is logging the key that is on barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue.
example: http://paste.openstack.org/show/481439/ |
|
2015-12-10 11:59:21 |
Akihiro Motoki |
tags |
|
lbaas |
|
2015-12-10 12:44:18 |
Akihiro Motoki |
description |
In liberty, a lbaasv2-agent is logging the key that is on barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue.
example: http://paste.openstack.org/show/481439/ |
In liberty, a neutron-lbaasv2-agent is logging credentials retrieved from barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue.
example: http://paste.openstack.org/show/481439/ |
|
2015-12-10 12:45:09 |
fujioka yuuichi |
description |
In liberty, a neutron-lbaasv2-agent is logging credentials retrieved from barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue.
example: http://paste.openstack.org/show/481439/ |
In liberty, a neutron-lbaasv2-agent is logging credentials retrieved from barbican when debug=True. (e.g. cert, private key, passphrase)
this makes security issue.
example: http://paste.openstack.org/show/481439/ (part of /var/log/neutron/neutron-lbaasv2-agent.log) |
|
2015-12-10 12:45:11 |
Akihiro Motoki |
summary |
lbaasv2 is logging key that is on barbican |
lbaasv2-agent is logging credentials from barbican |
|
2015-12-10 12:45:34 |
Akihiro Motoki |
neutron: importance |
Undecided |
High |
|
2015-12-10 15:27:57 |
Henry Gessau |
information type |
Public |
Private Security |
|
2015-12-10 15:41:58 |
Jeremy Stanley |
information type |
Private Security |
Public Security |
|
2015-12-10 15:43:50 |
Jeremy Stanley |
bug task added |
|
ossa |
|
2015-12-10 15:48:00 |
Jeremy Stanley |
ossa: status |
New |
Incomplete |
|
2015-12-16 00:32:52 |
OpenStack Infra |
neutron: status |
New |
In Progress |
|
2015-12-16 00:32:52 |
OpenStack Infra |
neutron: assignee |
|
Adam Harwell (adam-harwell) |
|
2016-01-05 19:44:28 |
Tristan Cacqueray |
ossa: status |
Incomplete |
Won't Fix |
|
2016-01-06 06:13:14 |
OpenStack Infra |
neutron: status |
In Progress |
Fix Released |
|