Project

General

Profile

Actions

Bug #23011

open

“SSH authorized keys” system technique breaks when changed from “audit” to “enforce” mode

Added by Michel BOUISSOU over 1 year ago. Updated 5 months ago.

Status:
New
Priority:
N/A
Assignee:
-
Category:
Techniques
Target version:
Severity:
Major - prevents use of part of Rudder | no simple workaround
UX impact:
User visibility:
Getting started - demo | first install | Technique editor and level 1 Techniques
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

If a directive is created in “audit” mode using the “SSH authorized keys” system technique with parameters as in attached screenshot, and after having been ran on the nodes, the directive is later on changed to “enforce” mode, then after being ran on the nodes again, their compliance displays a “bad policy mode” error as in attached screenshot.

Furthermore, if the directive is changed to “audit” mode again, it will display a spurious “The keys for user blah could not be flushed”, where the authorized_keys file do actually have the proper contents (thus should be considered compliant and shouldn't need to be flushed).


Files

authorized_keys_directive_parameters.png (111 KB) authorized_keys_directive_parameters.png Directive parameters Michel BOUISSOU, 2023-07-05 10:22
Bad_policy_mode_230705a.png (171 KB) Bad_policy_mode_230705a.png Error : bad policy mode. Michel BOUISSOU, 2023-07-05 10:24
authorized_keys_could_not_be_flushed.png (128 KB) authorized_keys_could_not_be_flushed.png “Could not be flushed” error message. Michel BOUISSOU, 2023-07-05 10:25
Bad_policy_mode_230706a.png (166 KB) Bad_policy_mode_230706a.png Error on freshly added node Michel BOUISSOU, 2023-07-06 10:03
Bad_policy_mode_230706b.png (189 KB) Bad_policy_mode_230706b.png Same error for directive recreated in enforce mode Michel BOUISSOU, 2023-07-06 15:27

Related issues 1 (0 open1 closed)

Related to Rudder - Bug #23027: Grammar correction in error messageReleasedFélix DALLIDETActions
Actions

Also available in: Atom PDF