Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1495267 - RFE: ovirt-log-collector-analyzer: hide fence passwords via switch
RFE: ovirt-log-collector-analyzer: hide fence passwords via switch
Status: CLOSED ERRATA
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: ovirt-log-collector (Show other bugs)
4.1.5
All All
unspecified Severity medium
: ovirt-4.2.0
: 4.2.0
Assigned To: Douglas Schilling Landgraf
Jiri Belka
: EasyFix, FutureFeature, Improvement
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-09-25 12:05 EDT by Douglas Schilling Landgraf
Modified: 2018-05-15 13:32 EDT (History)
7 users (show)

See Also:
Fixed In Version: ovirt-log-collector-4.2.0-1.el7ev
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-05-15 13:31:24 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: Integration
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
lsvaty: testing_plan_complete-


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
oVirt gerrit 82595 master MERGED inventory: Add --show-fence-agent-passwords 2017-10-16 11:39 EDT
Red Hat Product Errata RHBA-2018:1465 None None None 2018-05-15 13:32 EDT

  None (edit)
Description Douglas Schilling Landgraf 2017-09-25 12:05:45 EDT
Description of problem:

    User requested to hide encrypted fence passwords information via switch.
Comment 1 Sandro Bonazzola 2017-09-26 01:36:11 EDT
Can you please detail? I've not understood which password needs to be hidden and where.
Comment 2 Mark Keir 2017-09-26 01:44:29 EDT
Section 8 of the report under the heading:

"8. Fence agent password per host"
Comment 3 Dan Kenigsberg 2017-09-26 01:53:59 EDT
Why is that needed to be hidden? Another user WANTED us to capture them, so that it is easier to restore them when a host is removed and re-added to the same Engine.
Comment 4 Mark Keir 2017-09-26 02:39:51 EDT
Passwords are not normally exposed in reports shared between groups for analysis.  Some companies, Atlassian is an example, provide tools to make data dumps for support anonymous. 

I'd feel more comfortable if the default behaviour was to not include the fence passwords in the report for security.  If they were to be needed, they might be included in the report via a verbose|debug option.

When we write ansible code where credentials are involved, we normally use "no_log" to hide the credential.  It can be exposed for verification by turning up the "-vvv" level.
Comment 7 Jiri Belka 2018-01-26 08:19:12 EST
ok, ovirt-log-collector-analyzer-4.2.0-1.el7ev.noarch

tested with a sosreport from 4.1 env as with 4.2 env sosreport it has issue - https://bugzilla.redhat.com/show_bug.cgi?id=1539027
Comment 12 errata-xmlrpc 2018-05-15 13:31:24 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:1465

Note You need to log in before you can comment on or make changes to this bug.