Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1339677 - [RFE] Lock 'root' account and disable password authentication for Azure appliance
[RFE] Lock 'root' account and disable password authentication for Azure appli...
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Build (Show other bugs)
5.6.0
Unspecified Unspecified
high Severity high
: GA
: 5.6.0
Assigned To: Satoe Imaishi
Jeff Teehan
: FutureFeature
Depends On:
Blocks: 1350329
  Show dependency treegraph
 
Reported: 2016-05-25 10:55 EDT by Satoe Imaishi
Modified: 2017-08-29 21:40 EDT (History)
5 users (show)

See Also:
Fixed In Version: 5.6.0.10
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-06-29 12:05:40 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:1348 normal SHIPPED_LIVE CFME 5.6.0 bug fixes and enhancement update 2016-06-29 14:50:04 EDT

  None (edit)
Description Satoe Imaishi 2016-05-25 10:55:26 EDT
Description of problem:

Currently, the Azure appliance allows users to login with root/smartvm credentials unless password authentication is explicitly disabled at the time of VM creation.

The root account should be disabled and only allow login with ssh key by default.

Version-Release number of selected component (if applicable):
cfme-azure-5.6.0.7-1.x86_64.vhd


Actual results:


Expected results:


Additional info:
Comment 3 Oleg Barenboim 2016-05-26 17:33:47 EDT
https://github.com/ManageIQ/manageiq-appliance-build/pull/134 has been merged and backported to Darga.
Comment 4 CFME Bot 2016-05-26 17:45:40 EDT
New commit detected on ManageIQ/manageiq-appliance-build/master:
https://github.com/ManageIQ/manageiq-appliance-build/commit/b7176c51aa415fe1973c1fcc125de08593a1aacf

commit b7176c51aa415fe1973c1fcc125de08593a1aacf
Author:     Satoe Imaishi <simaishi@redhat.com>
AuthorDate: Tue May 24 18:10:01 2016 -0400
Commit:     Satoe Imaishi <simaishi@redhat.com>
CommitDate: Thu May 26 18:09:28 2016 -0400

    Disable password authentication and lock root account for Azure
    
    https://bugzilla.redhat.com/show_bug.cgi?id=1339677

 kickstarts/partials/post/azure.ks.erb | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)
Comment 6 Jeff Teehan 2016-06-08 14:53:22 EDT
jteehan@localhost openvpn]$ ssh root@23.96.119.41
The authenticity of host '23.96.119.41 (23.96.119.41)' can't be established.
ECDSA key fingerprint is SHA256:hr8fiYCkRign6oXbTFqMalEsmQJniJoD+efM20Zaa5s.
ECDSA key fingerprint is MD5:9a:50:a2:a0:f6:7e:5f:5e:7e:27:b6:14:48:e4:fc:19.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '23.96.119.41' (ECDSA) to the list of known hosts.
Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
[jteehan@localhost openvpn]$ 

Moving to Verified for 5.6.0.10
Comment 8 errata-xmlrpc 2016-06-29 12:05:40 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2016:1348

Note You need to log in before you can comment on or make changes to this bug.