Prior to this update, the ovirt plug-in for the sos utility did not properly obfuscate the passwords in the ovirt-engine setup answer file, and the passwords were thus collected in plain text format. With this update, the passwords are now obfuscated as intended, and no longer collected.
+++ This bug was initially created as a clone of Bug #1162781 +++
Description of problem:
Initial passwords leaked here: <rhevm-host-sosreport-tarball>/var/lib/ovirt-engine/setup/answers/YYYYMMDDHHMMSS-setup.conf
Version-Release number of selected component (if applicable):
3.X
How reproducible:
Steps to Reproduce:
1.
2.
3.
Actual results:
Expected results:
****** out passwords
Additional info:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://rhn.redhat.com/errata/RHBA-2015-2118.html