Bug 1154024 - packstack: clear text password for heat
Summary: packstack: clear text password for heat
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-packstack
Version: 5.0 (RHEL 7)
Hardware: x86_64
OS: Linux
high
medium
Target Milestone: z4
: 5.0 (RHEL 7)
Assignee: Gaël Chamoulaud
QA Contact: Ido Ovadia
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-10-17 09:47 UTC by Dafna Ron
Modified: 2023-02-22 23:02 UTC (History)
10 users (show)

Fixed In Version: openstack-packstack-2014.1.1-0.45.dev1279.el7ost
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-04-16 14:02:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-16612 0 None None None 2022-07-09 07:24:40 UTC
Red Hat Product Errata RHSA-2015:0831 0 normal SHIPPED_LIVE Important: openstack-packstack and openstack-puppet-modules update 2015-04-16 17:53:33 UTC

Description Dafna Ron 2014-10-17 09:47:53 UTC
Description of problem:

when installing packstack we can see the typed password entered for heat user in clear text: 

Enter password for Keystone domain admin user for Heat  [b2125bcb9f1e4fba] : seemypassword


Version-Release number of selected component (if applicable):

openstack-packstack-puppet-2014.1.1-0.41.dev1251.el7ost.noarch
openstack-packstack-2014.1.1-0.41.dev1251.el7ost.noarch


How reproducible:

100%

Steps to Reproduce:
1. install heat with packstack
2.
3.

Actual results:

the admin password is shown in clear text 

Expected results:

like the other components when running packstack, password should not be in clear text 

Additional info:

Comment 2 Gaël Chamoulaud 2014-10-20 12:17:33 UTC
Hi Dafna,

Your issue is already fixed in master [1] ! this commit should be included in the next rpm build.

[1] - https://review.openstack.org/#/c/122164/

Comment 6 Ivan Chavero 2015-03-25 21:24:05 UTC
Can i have qe ack for this bug please?

Thanks!

Comment 7 Ivan Chavero 2015-03-25 21:50:33 UTC
To verify this bug:


Run packstack interactive install and type new heat password when asked. 
The password should not appear on clear text.

Comment 9 Ido Ovadia 2015-03-29 18:11:23 UTC
Verified
========
openstack-packstack-2014.1.1-0.46.dev1280.el7ost.noarch

Comment 12 errata-xmlrpc 2015-04-16 14:02:57 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0831.html


Note You need to log in before you can comment on or make changes to this bug.