Bug 1234962 - /etc/puppet/hieradata should not world readable on the undercloud
Summary: /etc/puppet/hieradata should not world readable on the undercloud
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: instack-undercloud
Version: Director
Hardware: Unspecified
OS: Unspecified
high
unspecified
Target Milestone: ga
: Director
Assignee: James Slagle
QA Contact: Marius Cornea
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-06-23 15:16 UTC by James Slagle
Modified: 2023-02-22 23:02 UTC (History)
4 users (show)

Fixed In Version: instack-undercloud-2.1.2-8.el7ost
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-08-05 13:55:37 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Gerrithub.io 237535 0 None None None Never
Red Hat Product Errata RHEA-2015:1549 0 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform director Release 2015-08-05 17:49:10 UTC

Description James Slagle 2015-06-23 15:16:48 UTC
/etc/puppet/hieradata should not world readable on the undercloud

Correct permissions should be 751, but they are actually 755

Comment 3 James Slagle 2015-06-24 20:39:55 UTC
upstream patch: https://review.gerrithub.io/237535

Comment 4 Mike Burns 2015-06-29 22:17:37 UTC
move to on_dev until patch gets merged.

Comment 6 Marius Cornea 2015-07-13 19:05:25 UTC
[root@instack ~]# rpm -qa | grep  instack-undercloud; ls -ld /etc/puppet/hieradata; ls -l /etc/puppet/hieradata

instack-undercloud-2.1.2-17.el7ost.noarch
drwxr-x---. 2 root root 4096 Jul 13 08:10 /etc/puppet/hieradata
total 12
-rw-------. 1 root root 12216 Jul 13 08:10 puppet-stack-config.yaml

Comment 8 errata-xmlrpc 2015-08-05 13:55:37 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1549


Note You need to log in before you can comment on or make changes to this bug.