Potential privilege escalation with the default libvirtd TLS config
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | tripleo |
High
|
Juan Antonio Osorio Robles | ||
Bug Description
With the default TLS setup, any service with a certificate from the CA will be granted access to libvirtd.
There are a number of options to address this:
- use a different CA just for libvirt access
- filter allowed clients
- enable SASL auth for libvirtd
- disabled libvirt TLS
CVE References
| Steven Hardy (shardy) wrote : | #1 |
| Changed in tripleo: | |
| status: | New → Triaged |
| importance: | Undecided → High |
| milestone: | none → queens-2 |
| Emilien Macchi (emilienm) wrote : | #2 |
We should reach Summer Long <email address hidden> if whether or not embargo is required on this issue, and if a CVE is accurate.
| Emilien Macchi (emilienm) wrote : | #3 |
IMHO, we should use enable SASL auth for libvirtd and filter allowed clients at minimum.
Having an dedicated CA is good but I think not enough; I like the SASL layer for credentials, which will allow us to have granular authentification and enable PolicyKit for example.
| Oliver Walsh (owalsh) wrote : | #4 |
Do we have puppet support for managing SASL?
| Oliver Walsh (owalsh) wrote : | #5 |
BTW we had to drop polkit when we containerized this.
| Joshua Padman (jpadman) wrote : Re: [Bug 1730370] Re: Potential privilege escalation with the default libvirtd TLS config | #6 |
Thank you for the add and the info. Summer Long normally takes Director
etc but Summit!
Cheers,
Josh
On 07/11/17 12:30, Oliver Walsh wrote:
> BTW we had to drop polkit when we containerized this.
>
--
Joshua Padman / Red Hat Product Security
| Oliver Walsh (owalsh) wrote : | #7 |
Libvirt TLS has been disabled in https:/
| information type: | Private Security → Public Security |
| Changed in tripleo: | |
| status: | Triaged → Fix Released |
| OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/tripleo-heat-templates 8.0.0.0b2 | #8 |
This issue was fixed in the openstack/


Triaged as this is already assigned, we should discuss the plan for merging/backporting before making this public,