rabbitmq.config should not allow for unauth connections from localhost

Bug #1352308 reported by Giulio Fidente
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
Invalid
Wishlist
Giulio Fidente

Bug Description

we're manually allowing for unauth accesso to rabbitmq from localhost as this was the default rabbitmq config with previous rabbitmq versions

we shouldn't need to do that though as all services should be provided with appropriate credentials to login on rabbit and should not point to localhost (but either have a list of rabbit nodes or point to the VIP)

Changed in tripleo:
assignee: nobody → Giulio Fidente (gfidente)
Revision history for this message
Ben Nemec (bnemec) wrote :

I believe https://review.openstack.org/#/c/91861/1 is related to this.

Changed in tripleo:
status: New → Triaged
importance: Undecided → Medium
Revision history for this message
Giulio Fidente (gfidente) wrote :

yep, some cleanup needed in the rabbitmq.config file after that is merged to deny unauth connections

Revision history for this message
Steven Hardy (shardy) wrote : potentially eol bug

This bug was reported against an old version of TripleO, and may no longer be valid.

Since it was reported before the start of the liberty cycle (and our oldest stable
branch is stable/liberty), I'm marking this incomplete.

Please reopen this (change the status from incomplete) if the bug is still valid
on a current supported (stable/liberty, stable/mitaka or trunk) version of TripleO,
thanks!

Changed in tripleo:
status: Triaged → Incomplete
Changed in tripleo:
importance: Medium → Wishlist
Revision history for this message
Emilien Macchi (emilienm) wrote :

This bug was last updated over 180 days ago, as tripleo is a fast moving project and we'd like to get the tracker down to currently actionable bugs, this is getting marked as Invalid. If the issue still exists, please feel free to reopen it.

Changed in tripleo:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.