The following setting is linux only. The documentation already states that it works by updating directly the /etc/shadow file, but this is not explicit enough and users might think that by setting inject_password to True it will work on Windows instances as well.
[libvirt]
inject_password=true
The article should also specify that if the password is provided via nova CLI or Horizon (can_set_password = True), this will only be available in the metadata when a configdrive is used (admin_pass in meta_data.son).
The password is not included in the corresponding HTTP metadata (e.g. http://169.254.169.254/openstack/latest/meta_data.json).
Additionally, it should be clearly stated that clear text passwords are a security risk and that Nova provides a secure way to handle passwords with "nova get-password" since Grizzly.
-----------------------------------
Built: 2015-05-14T07:06:14 00:00
git SHA: c48b1257234e95a1e74f10bbe84318c4f63fdbed
URL: http://docs.openstack.org/admin-guide-cloud/content/admin-password-injection.html
source File: file:/home/jenkins/workspace/openstack-manuals-tox-doc-publishdocs/doc/admin-guide-cloud/compute/section_compute-system-admin.xml
xml:id: admin-password-injection
Fix proposed to branch: master /review. openstack. org/183093
Review: https:/