Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1154024 - packstack: clear text password for heat
packstack: clear text password for heat
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-packstack (Show other bugs)
5.0 (RHEL 7)
x86_64 Linux
high Severity medium
: z4
: 5.0 (RHEL 7)
Assigned To: Gaël Chamoulaud
Ido Ovadia
: ZStream
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-10-17 05:47 EDT by Dafna Ron
Modified: 2015-04-16 10:02 EDT (History)
11 users (show)

See Also:
Fixed In Version: openstack-packstack-2014.1.1-0.45.dev1279.el7ost
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-04-16 10:02:57 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0831 normal SHIPPED_LIVE Important: openstack-packstack and openstack-puppet-modules update 2015-04-16 13:53:33 EDT

  None (edit)
Description Dafna Ron 2014-10-17 05:47:53 EDT
Description of problem:

when installing packstack we can see the typed password entered for heat user in clear text: 

Enter password for Keystone domain admin user for Heat  [b2125bcb9f1e4fba] : seemypassword


Version-Release number of selected component (if applicable):

openstack-packstack-puppet-2014.1.1-0.41.dev1251.el7ost.noarch
openstack-packstack-2014.1.1-0.41.dev1251.el7ost.noarch


How reproducible:

100%

Steps to Reproduce:
1. install heat with packstack
2.
3.

Actual results:

the admin password is shown in clear text 

Expected results:

like the other components when running packstack, password should not be in clear text 

Additional info:
Comment 2 Gaël Chamoulaud 2014-10-20 08:17:33 EDT
Hi Dafna,

Your issue is already fixed in master [1] ! this commit should be included in the next rpm build.

[1] - https://review.openstack.org/#/c/122164/
Comment 6 Ivan Chavero 2015-03-25 17:24:05 EDT
Can i have qe ack for this bug please?

Thanks!
Comment 7 Ivan Chavero 2015-03-25 17:50:33 EDT
To verify this bug:


Run packstack interactive install and type new heat password when asked. 
The password should not appear on clear text.
Comment 9 Ido Ovadia 2015-03-29 14:11:23 EDT
Verified
========
openstack-packstack-2014.1.1-0.46.dev1280.el7ost.noarch
Comment 12 errata-xmlrpc 2015-04-16 10:02:57 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0831.html

Note You need to log in before you can comment on or make changes to this bug.