Project

General

Profile

Actions

Bug #13657

closed

Script rudder-support-info does not mask credentials

Added by Janos Mattyasovszky about 6 years ago. Updated over 5 years ago.

Status:
Released
Priority:
N/A
Category:
Agent
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Operational - other Techniques | Rudder settings | Plugins
Effort required:
Very Small
Priority:
95
Name check:
Fix check:
Regression:

Description

Following things should be anonymized:

- rudder.auth.ldap.connection.bind.password in ./rudder/rudder-web.properties


Subtasks 1 (0 open1 closed)

Bug #14829: Error in parent ticket - missing Digest/SHA.pm as a dependency on centosReleasedNicolas CHARLESActions
Actions #1

Updated by Alexis Mousset about 6 years ago

  • Category set to Agent
Actions #2

Updated by François ARMAND about 6 years ago

  • Effort required set to Very Small
Actions #3

Updated by Benoît PECCATTE over 5 years ago

  • Severity set to Critical - prevents main use of Rudder | no workaround | data loss | security
  • User visibility set to Operational - other Techniques | Rudder settings | Plugins
  • Priority changed from 0 to 96
Actions #4

Updated by François ARMAND over 5 years ago

  • Assignee set to Nicolas CHARLES
Actions #5

Updated by Nicolas CHARLES over 5 years ago

we should anonymise:
  • syslog/rsyslog.d/rudder.conf : anonymise password in line that contains :ompgsql:ip,db, user,PGPW;RudderReportsFormat
  • rudder/rudder-web.properties , PGPW and LDAPPW
  • rudder/inventory-web.properties : LDAPPW

Idealy, if we could anonymize it in a way taht let us detect if values are the same, it would be great for debuuging

Actions #6

Updated by Nicolas CHARLES over 5 years ago

  • Target version set to 5.0.10
Actions #7

Updated by Nicolas CHARLES over 5 years ago

  • Status changed from New to In progress
Actions #9

Updated by Nicolas CHARLES over 5 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Nicolas CHARLES to Benoît PECCATTE
  • Pull Request set to https://github.com/Normation/rudder-packages/pull/1857
Actions #10

Updated by Nicolas CHARLES over 5 years ago

  • Status changed from Pending technical review to Pending release
Actions #11

Updated by Vincent MEMBRÉ over 5 years ago

  • Status changed from Pending release to Released
  • Priority changed from 96 to 95

This bug has been fixed in Rudder 5.0.10 which was released today.

Actions

Also available in: Atom PDF