Back to bug 1391571

Who When What Removed Added
Garth Mollett 2016-11-03 23:09:18 UTC CC gmollett
Jon Schlueter 2017-02-14 10:55:09 UTC Status NEW POST
Link ID OpenStack gerrit 383432
Jon Schlueter 2017-02-14 10:57:20 UTC Keywords Triaged, ZStream
Target Release --- 10.0 (Newton)
Jon Schlueter 2017-02-14 11:03:11 UTC Link ID OpenStack gerrit 383434
Jon Schlueter 2017-03-16 11:47:29 UTC Assignee rhos-maint jschluet
Doc Text Cause: if running with debug and -vv user password is emitted in plain text

Consequence: user password is exposed

Fix: mask the password using oslo_utils.strutils.mask_password()

Result: the user's password no longer logged in plain text
Doc Type If docs needed, set a value Bug Fix
Jon Schlueter 2017-03-16 11:59:40 UTC Status POST MODIFIED
Fixed In Version python-osc-lib-1.1.0-3.el7ost
Jon Schlueter 2017-03-16 12:24:25 UTC Fixed In Version python-osc-lib-1.1.0-3.el7ost python-osc-lib-1.1.0-3.el7ost python-openstackclient-3.2.1-1.el7ost
Jon Schlueter 2017-03-16 12:24:38 UTC Target Milestone --- z3
errata-xmlrpc 2017-03-16 17:40:54 UTC Status MODIFIED ON_QA
Julie Pichon 2017-05-23 15:08:10 UTC Keywords OtherQA
Status ON_QA VERIFIED
CC jpichon
QA Contact nlevinki jpichon
Lukas Ruzicka 2017-06-09 08:55:21 UTC CC lruzicka
Doc Text Cause: if running with debug and -vv user password is emitted in plain text

Consequence: user password is exposed

Fix: mask the password using oslo_utils.strutils.mask_password()

Result: the user's password no longer logged in plain text
When the openstack client ran in debug or verbose mode, the user password was displayed as plain text in the output. The problem has been fixed using the oslo password masking utility. As a result, user passwords are not displayed in plain text any more.
Flags needinfo?(jschluet)
errata-xmlrpc 2017-06-28 01:15:42 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2017-06-28 15:27:21 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2017-06-28 11:27:21 UTC
Jon Schlueter 2017-07-31 12:11:49 UTC Flags needinfo?(jschluet)

Back to bug 1391571