Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1154024

Summary: packstack: clear text password for heat
Product: Red Hat OpenStack Reporter: Dafna Ron <dron>
Component: openstack-packstackAssignee: Gaël Chamoulaud <gchamoul>
Status: CLOSED ERRATA QA Contact: Ido Ovadia <iovadia>
Severity: medium Docs Contact:
Priority: high    
Version: 5.0 (RHEL 7)CC: aberezin, aortega, derekh, gchamoul, ichavero, sasha, sclewis, scohen, slong, yeylon
Target Milestone: z4Keywords: ZStream
Target Release: 5.0 (RHEL 7)   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: openstack-packstack-2014.1.1-0.45.dev1279.el7ost Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-04-16 14:02:57 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dafna Ron 2014-10-17 09:47:53 UTC
Description of problem:

when installing packstack we can see the typed password entered for heat user in clear text: 

Enter password for Keystone domain admin user for Heat  [b2125bcb9f1e4fba] : seemypassword


Version-Release number of selected component (if applicable):

openstack-packstack-puppet-2014.1.1-0.41.dev1251.el7ost.noarch
openstack-packstack-2014.1.1-0.41.dev1251.el7ost.noarch


How reproducible:

100%

Steps to Reproduce:
1. install heat with packstack
2.
3.

Actual results:

the admin password is shown in clear text 

Expected results:

like the other components when running packstack, password should not be in clear text 

Additional info:

Comment 2 Gaël Chamoulaud 2014-10-20 12:17:33 UTC
Hi Dafna,

Your issue is already fixed in master [1] ! this commit should be included in the next rpm build.

[1] - https://review.openstack.org/#/c/122164/

Comment 6 Ivan Chavero 2015-03-25 21:24:05 UTC
Can i have qe ack for this bug please?

Thanks!

Comment 7 Ivan Chavero 2015-03-25 21:50:33 UTC
To verify this bug:


Run packstack interactive install and type new heat password when asked. 
The password should not appear on clear text.

Comment 9 Ido Ovadia 2015-03-29 18:11:23 UTC
Verified
========
openstack-packstack-2014.1.1-0.46.dev1280.el7ost.noarch

Comment 12 errata-xmlrpc 2015-04-16 14:02:57 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0831.html