Hide Forgot
Description of problem: The Capsule reverse proxy to the Satellite is not limited to e.g. the API only. It allows full access all possible the Satellite data. This includes also the /var/www/html/pub directory under /pub. And also the UI. A secret file in the pub on the satellite [crash] root@li-lc-1578:~# cat /var/www/html/pub/secret_dir/secret_file secret file On a client through capsule li-lc-1589 i can download the file from li-lc-1578 [crash] root@li-lc-1442:~# curl -k https://li-lc-1589.hag.hilti.com:8443/pub/secret_dir/secret_file secret file Version-Release number of selected component (if applicable): How reproducible: Steps to Reproduce: 1. Create a file in Satellite mkdir -p /var/www/html/pub/secret_dir echo "secret file" > /var/www/html/pub/secret_dir/secret_file 2. Download the file through the capsule https://capsule.com:8443/pub/secret_dir/secret_file.txt 3. Actual results: Expected results: Additional info:
Additional there is a special case for pulp-https that also does a reverse proxy for katello/api/repositories: [crash] root@li-lc-1589:/etc/httpd/conf.d# grep -R ProxyPass 28-katello-reverse-proxy.conf: ProxyPass / https://li-lc-1578.hag.hilti.com/ 28-katello-reverse-proxy.conf: ProxyPassReverse / / 28-katello-reverse-proxy.conf: ProxyPassReverse / https://li-lc-1578.hag.hilti.com/ 05-pulp-https.conf: ProxyPass /katello/api/repositories/ https://li-lc-1578.hag.hilti.com/katello/api/repositories/ 05-pulp-https.conf: ProxyPassReverse https://li-lc-1578.hag.hilti.com/
Thank you for your interest in Satellite 6. We have evaluated this request, and we do not expect this to be implemented in the product in the foreseeable future. We are therefore closing this out as WONTFIX. If you have any concerns about this, please feel free to contact Rich Jerrido or Bryan Kearney. Thank you.