Bug 1495267 - RFE: ovirt-log-collector-analyzer: hide fence passwords via switch
Summary: RFE: ovirt-log-collector-analyzer: hide fence passwords via switch
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: ovirt-log-collector
Version: 4.1.5
Hardware: All
OS: All
unspecified
medium
Target Milestone: ovirt-4.2.0
: 4.2.0
Assignee: Douglas Schilling Landgraf
QA Contact: Jiri Belka
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-09-25 16:05 UTC by Douglas Schilling Landgraf
Modified: 2019-05-16 13:09 UTC (History)
6 users (show)

Fixed In Version: ovirt-log-collector-4.2.0-1.el7ev
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-15 17:31:24 UTC
oVirt Team: Integration
Target Upstream Version:
Embargoed:
lsvaty: testing_plan_complete-


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:1465 0 None None None 2018-05-15 17:32:08 UTC
oVirt gerrit 82595 0 master MERGED inventory: Add --show-fence-agent-passwords 2021-01-29 16:27:17 UTC

Description Douglas Schilling Landgraf 2017-09-25 16:05:45 UTC
Description of problem:

    User requested to hide encrypted fence passwords information via switch.

Comment 1 Sandro Bonazzola 2017-09-26 05:36:11 UTC
Can you please detail? I've not understood which password needs to be hidden and where.

Comment 2 Mark Keir 2017-09-26 05:44:29 UTC
Section 8 of the report under the heading:

"8. Fence agent password per host"

Comment 3 Dan Kenigsberg 2017-09-26 05:53:59 UTC
Why is that needed to be hidden? Another user WANTED us to capture them, so that it is easier to restore them when a host is removed and re-added to the same Engine.

Comment 4 Mark Keir 2017-09-26 06:39:51 UTC
Passwords are not normally exposed in reports shared between groups for analysis.  Some companies, Atlassian is an example, provide tools to make data dumps for support anonymous. 

I'd feel more comfortable if the default behaviour was to not include the fence passwords in the report for security.  If they were to be needed, they might be included in the report via a verbose|debug option.

When we write ansible code where credentials are involved, we normally use "no_log" to hide the credential.  It can be exposed for verification by turning up the "-vvv" level.

Comment 7 Jiri Belka 2018-01-26 13:19:12 UTC
ok, ovirt-log-collector-analyzer-4.2.0-1.el7ev.noarch

tested with a sosreport from 4.1 env as with 4.2 env sosreport it has issue - https://bugzilla.redhat.com/show_bug.cgi?id=1539027

Comment 12 errata-xmlrpc 2018-05-15 17:31:24 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:1465

Comment 13 Franta Kust 2019-05-16 13:05:30 UTC
BZ<2>Jira Resync


Note You need to log in before you can comment on or make changes to this bug.