Project

General

Profile

Actions

User story #6589

closed

Improve Rudder security in 3.1: Inventory signature and security, SELinux compliance

User story #6589: Improve Rudder security in 3.1: Inventory signature and security, SELinux compliance

Added by Benoît PECCATTE over 11 years ago. Updated about 11 years ago.

Status:
Released
Priority:
N/A
Assignee:
-
Category:
System integration
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

- Sign inventories before sending them
- Verify inventory signature upon reception
- Send inventories with https
- Limit inventory reception to allowed networks
- Limit reports reception to known nodes
- Allow Rudder to run with SELinux


Subtasks 32 (0 open32 closed)

Architecture #6356: Inventory endpoint should validate agent signatureReleasedFrançois ARMANDActions
Architecture #6506: Change send_clean to push signature along with inventoryReleasedMatthieu CERDAActions
Architecture #6558: Update test in Rudder so it is ok with new inventory data modelReleasedFrançois ARMANDActions
User story #6560: Display key used to sign inventory and if the Node is "Certified"ReleasedFrançois ARMANDActions
Architecture #6567: Add a script to manage node keys on serverReleasedVincent MEMBRÉActions
Bug #6583: Can't validate inventory key stored with old formatReleasedNicolas CHARLESActions
Bug #6584: Tests broken with wrong inventory schemaReleasedNicolas CHARLESActions
Bug #6600: Cannot modify root server inventory after new installReleasedFrançois ARMANDActions
Bug #6601: Remove invalid default public key for root serverReleasedFrançois ARMANDActions
User story #6578: Upload inventory with https by defaultReleasedNicolas CHARLESActions
User story #2882: Rudder should be SELinux compliantReleasedBenoît PECCATTEActions
Question #6467: What are the webdav directories used for ?ResolvedBenoît PECCATTEActions
Architecture #6517: Authorize on SELinux directories used for webdav on the serverReleasedBenoît PECCATTEActions
Bug #6556: rudder-webapp is using a wrong file in spec file for SELinux policyReleasedFrançois ARMANDActions
Bug #6597: Rudder webapp postinst are not validReleasedBenoît PECCATTEActions
Bug #6598: rudder selinux module is not workingReleasedBenoît PECCATTEActions
Bug #6652: rudder-webapp SELinux-related BuildRequires are neither advertised nor usable on all systemsReleasedBenoît PECCATTEActions
User story #6672: Remove packaging of rudder-webapp.pp on debianReleasedMatthieu CERDAActions
Bug #6679: The SELinux compilation in rudder-webapp ties to use the wrong directory as a baseReleasedBenoît PECCATTEActions
Bug #6681: rudder-webapp spec tries to copy rudder-webapp.pp from wrong directoryReleasedMatthieu CERDAActions
Bug #6682: rudder-webapp spec tries to build rudder-webapp.pp even if he can'tReleasedMatthieu CERDAActions
Architecture #6355: Agent should sign their inventory using their private keyReleasedActions
Architecture #6477: Create a script to sign files using openssl on unixReleasedMatthieu CERDAActions
Bug #6592: signature.sh is not in the final packageReleasedVincent MEMBRÉActions
Architecture #6510: Inventory technique should create a signature and send itReleasedVincent MEMBRÉActions
Architecture #6515: Add openssl command line on windows - toolsReleasedBenoît PECCATTEActions
Architecture #6516: Add dependency to openssl command on debianReleasedBenoît PECCATTEActions
Bug #6535: Cannot build rudder-agent-thin 3.1, cannot apply patchesReleasedVincent MEMBRÉActions
Bug #6687: bundle sendInventoryToCmdb tries to send .sign files to the endpointReleasedBenoît PECCATTEActions
Bug #6692: Syntax error in site.cfReleasedMatthieu CERDAActions
Bug #6551: signature.sh doesn't use absolute key pathReleasedVincent MEMBRÉActions
User story #6739: Sign inventories on WindowsReleasedBenoît PECCATTEActions

Related issues 1 (0 open1 closed)

Related to Rudder - User story #6363: Secure agent/server communicationReleasedActions

Updated by Benoît PECCATTE over 11 years ago Actions #1

  • Description updated (diff)

Updated by Vincent MEMBRÉ over 11 years ago Actions #2

  • Target version changed from 3.1.0~beta1 to 3.1.0~rc1

Updated by Benoît PECCATTE over 11 years ago Actions #3

Updated by Vincent MEMBRÉ about 11 years ago Actions #4

  • Subject changed from Improve Rudder security in 3.1 to Improve Rudder security in 3.1: Inventory signature and security, SELinux compliance
  • Status changed from New to In progress

Updated by Vincent MEMBRÉ about 11 years ago Actions #5

  • Status changed from In progress to 12

Updated by Vincent MEMBRÉ about 11 years ago Actions #6

  • Status changed from 12 to Pending release

Updated by Vincent MEMBRÉ about 11 years ago Actions #7

  • Category changed from Architecture - Code maintenance to System integration

Updated by Vincent MEMBRÉ about 11 years ago Actions #8

  • Target version changed from 3.1.0~rc1 to 3.1.0~beta1

Updated by Vincent MEMBRÉ about 11 years ago Actions #9

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 3.1.0~beta1 which were released today.

Actions

Also available in: PDF Atom