Bug 1040975

Summary: [engine-setup][security] Proxy server password is visible in cli
Product: Red Hat Enterprise Virtualization Manager Reporter: Jiri Belka <jbelka>
Component: ovirt-engine-setupAssignee: Sandro Bonazzola <sbonazzo>
Status: CLOSED CURRENTRELEASE QA Contact: Meni Yakove <myakove>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 3.3.0CC: aberezin, acathrow, bazulay, iheim, myakove, oschreib, pstehlik, Rhev-m-bugs, sbonazzo, yeylon
Target Milestone: ---Keywords: Triaged
Target Release: 3.3.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: integration
Fixed In Version: rhevm-setup-plugins-3.3.0-4.el6ev Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Jiri Belka 2013-12-12 12:57:52 UTC
Description of problem:

-%-
engine-setup
...snip...         
          Would you like transactions from the Red Hat Access Plugin sent from the RHEV Manager to be brokered through a proxy server? (Yes, No) 
[No]: Yes
          Please enter your proxy server so that the Red Hat Access Plug-in can reach access.redhat.com.[http://localhost]: 
          Please enter the port of your proxy server. [3128]: 
          If your proxy server requires a user name, please enter it now [username]: 
          Proxy server password: verysecretpassword
                                 ^^^^^^^^^^^^^^^^^^ ??????????????????
-%-

Version-Release number of selected component (if applicable):
is26/rhevm-setup-3.3.0-0.39.rc.el6ev.noarch redhat-support-plugin-rhev-3.3.0-13.el6ev.noarch

How reproducible:
100%

Steps to Reproduce:
1. Yes for use proxy
2. enter
3. put some password

Actual results:
password is visible

Expected results:
hidden as other passwords

Additional info:

Comment 3 Meni Yakove 2013-12-23 10:23:55 UTC
rhevm-3.3.0-0.41.el6ev.noarch

Comment 4 Itamar Heim 2014-01-21 22:20:33 UTC
Closing - RHEV 3.3 Released

Comment 5 Itamar Heim 2014-01-21 22:26:12 UTC
Closing - RHEV 3.3 Released