Bug 1370376 - disabling snmpd v1 and v2c on overcloud
Summary: disabling snmpd v1 and v2c on overcloud
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: rhosp-director
Version: 8.0 (Liberty)
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: ---
Assignee: Pradeep Kilambi
QA Contact: Omri Hochman
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-08-26 05:48 UTC by PURANDHAR SAIRAM MANNIDI
Modified: 2019-12-16 06:30 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-10-13 05:45:37 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description PURANDHAR SAIRAM MANNIDI 2016-08-26 05:48:19 UTC
Description of problem:
Disabled snmp v1 and v2c on both the overcloud and undercloud. Only v3 is used.
Director deploys and used v3 by default but it leaves default community strings and v1 and v2c open. Need to understand the implications for ceilometer and any other cloud services.

Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1.
With director the following setting are enabled from templates:

    snmp::ro_community: 'xxxx'
    snmp::ro_community6: 'xxxx'
    snmp::com2sec: []
    snmp::com2sec6: []
    snmp::groups: []
    snmp::accesses: []
    snmp::views: []

2.snmpwalk -v1 -c public x.x.x.x
Timeout: No Response from x.x.x.x
3.snmpwalk -v2c -c public x.x.x.x
Timeout: No Response from x.x.x.x


Actual results:
default community strings and v1 and v2c open.

Expected results:
Should not see anything related to v1 and v2c information in SNMPD

Additional info:

Comment 5 Sadique Puthen 2016-08-26 09:29:35 UTC
Hi All, We suspect that ceilometer collects data from snmp on the overcloud nodes. Using ceilometer api, this data may be retrieved. Undercloud may be getting these data from overcloud ceilometer for some purpose. It's possible that ceilometer is configured to use public rocommunity string to retrieve these details.

We need a confirmation from Engineering.

Is there any impact by changing this string "public" to something else?
If it's expected that ceilometer may fail to get the details because its configured to query using public community, how do we change this in ceilometer?

Comment 6 PURANDHAR SAIRAM MANNIDI 2016-09-22 01:35:36 UTC
Can we have any update on the info requested?


Note You need to log in before you can comment on or make changes to this bug.