Bug 1014115 - engine-setup sometimes logs passwords
engine-setup sometimes logs passwords
Product: oVirt
Classification: Community
Component: ovirt-engine-installer (Show other bugs)
Unspecified Unspecified
urgent Severity urgent
: ---
: 3.3
Assigned To: Yedidyah Bar David
Jiri Belka
Depends On: 1014552
Blocks: 1011800 1016012
  Show dependency treegraph
Reported: 2013-10-01 08:44 EDT by Yedidyah Bar David
Modified: 2013-11-07 03:26 EST (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1016012 (view as bug list)
Last Closed: 2013-11-07 03:26:38 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
oVirt gerrit 19775 None None None Never
oVirt gerrit 19938 None None None Never
oVirt gerrit 19939 None None None Never

  None (edit)
Description Yedidyah Bar David 2013-10-01 08:44:09 EDT
Description of problem:

engine-setup sometimes logs passwords to its log file, although most of the code is intended to not do that. We should make sure this never happens.

Version-Release number of selected component (if applicable):

How reproducible:

E.g. while upgrading from legacy, the database-access password used by legacy is logged.

Steps to Reproduce:
1. Install ovirt 3.2, run setup, input some password for the database
2. Upgrade to 3.3

Actual results:

The db password appears in the log

Expected results:

All passwords should be replaced by '**FILTERED**'

Additional info:
Comment 1 Sandro Bonazzola 2013-10-14 05:57:49 EDT
included in now in updates-testing.
Comment 2 Jiri Belka 2013-10-25 06:47:15 EDT
ok, sf21.1 -> is20.
Comment 3 Sandro Bonazzola 2013-11-07 03:26:38 EST
oVirt has been released.

Note You need to log in before you can comment on or make changes to this bug.