| Summary: | Override passwords in command line arguments | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Marc Muehlfeld <mmuehlfe> |
| Component: | ipa | Assignee: | IPA Maintainers <ipa-maint> |
| Status: | CLOSED DUPLICATE | QA Contact: | ipa-qe <ipa-qe> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.3 | CC: | akasurde, jpazdziora, pasik, pvoborni, rcritten |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-05-11 14:20:00 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Marc Muehlfeld
2016-08-29 09:59:01 UTC
To be safe, you should enter password interactively to terminal. This is not issue on replicas, just first master. mysql uses dark magic and I have doubts that this is possible for python (simple change for sys.argv[0]='something' does not work) http://unix.stackexchange.com/questions/88665/how-does-ps-know-to-hide-passwords I propose wont/cantfix. I would like to not hack python using C For replicas I meant to use OTP password, it can be shown in ps output. I still dont think this is good idea to hack python found this, I dont like it: https://github.com/dvarrazzo/py-setproctitle however package is in Fedora and RHEL python-setproctitle Upstream ticket: https://fedorahosted.org/freeipa/ticket/6314 Even if the process changes argv to obfuscate the password strings, there will still be small time interval when the values are visible. Isn't it better to focus on methods when the passwords are not passed as command line parameters, than create false sense of security? I'm with Jan here. Something like https://fedorahosted.org/freeipa/ticket/4517 should be the fix. For upcoming months or more the FreeIPA/IdM team is focusing on stability, testability of FreeIPA/IdM and thus postponing any RFEs or non-critical bugs. This will be fixed by using the filehanlders or env vars as proposed in bug 1211603 *** This bug has been marked as a duplicate of bug 1211603 *** |