Bug 1540627 - logs are world-readable
Summary: logs are world-readable
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: ovirt-engine-dwh
Classification: oVirt
Component: Packaging.rpm
Version: 4.2.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ovirt-4.2.2
: ---
Assignee: Ido Rosenzwig
QA Contact: Jiri Belka
URL:
Whiteboard:
Depends On:
Blocks: 1475130 1631198 1631202
TreeView+ depends on / blocked
 
Reported: 2018-01-31 14:38 UTC by Yedidyah Bar David
Modified: 2018-12-10 09:24 UTC (History)
7 users (show)

Fixed In Version: ovirt-engine-dwh-4.2.2.1
Clone Of: 1540622
Environment:
Last Closed: 2018-03-29 11:13:32 UTC
oVirt Team: Integration
Embargoed:
rule-engine: ovirt-4.2+
rule-engine: exception+
sbonazzo: devel_ack+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
oVirt gerrit 87555 0 master MERGED spec: Change permissions for /var/log/ovirt-engine-dwh 2018-02-13 11:59:39 UTC
oVirt gerrit 87760 0 ovirt-engine-dwh-4.2 MERGED spec: Change permissions for /var/log/ovirt-engine-dwh 2018-02-18 08:07:41 UTC

Description Yedidyah Bar David 2018-01-31 14:38:32 UTC
Same as below, for /var/log/ovirt-engine-dwh

+++ This bug was initially created as a clone of Bug #1540622 +++

Description of problem:

/var/log/ovirt-engine, including everything underneath, is world-readable.

We protect sensitive information by filtering it out of these logs, but when we add new such information, sometimes a rather long time passes between adding it and someone noticing that it's not filtered out.

So we should make all these directories readable only as needed.

Didn't check what's the minimum that's working well - since we have there things written by user 'ovirt' and other things by user 'root', need to verify that if we change to ovirt:ovirt 0700, root is not prevented access (e.g. by selinux), or find some other solution.

Version-Release number of selected component (if applicable):

Forever.

How reproducible:

100%

Steps to Reproduce:
1. Setup engine
2. Add a host
3.

Actual results:

All logs are readable by every local user on the machine.

Expected results:

All relevant logs are readable (at most) by users ovirt and root.

Additional info:

Comment 1 Red Hat Bugzilla Rules Engine 2018-02-15 16:13:02 UTC
Target release should be placed once a package build is known to fix a issue. Since this bug is not modified, the target version has been reset. Please use target milestone to plan a fix for a oVirt release.

Comment 2 Jiri Belka 2018-03-07 12:03:17 UTC
ok, ovirt-engine-dwh-setup-4.2.2.1-1.el7ev.noarch

Comment 3 Sandro Bonazzola 2018-03-29 11:13:32 UTC
This bugzilla is included in oVirt 4.2.2 release, published on March 28th 2018.

Since the problem described in this bug report should be
resolved in oVirt 4.2.2 release, it has been closed with a resolution of CURRENT RELEASE.

If the solution does not work for you, please open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.