Bug 1807789 - Root password in the provisioning settings should be encrypted instead of plain text.
Summary: Root password in the provisioning settings should be encrypted instead of pla...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Settings
Version: 6.7.0
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: 6.9.0
Assignee: Suraj Patil
QA Contact: Omkar Khatavkar
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-02-27 09:32 UTC by Vedashree Deshpande
Modified: 2023-03-24 17:03 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-04-21 13:12:29 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 29967 0 Normal Closed Root password in the provisioning settings should be encrypted instead of plain text. 2020-11-30 05:17:05 UTC

Description Vedashree Deshpande 2020-02-27 09:32:31 UTC
Description of problem:
If you navigate to Administer -> Settings and view the Root password option on the Provisioning tab, the value is not masked which ideally it should be.  

Version-Release number of selected component (if applicable):
Red Hat Satellite 6.7 public beta. 

How reproducible:
If you navigate to Administer -> Settings and view the Root password option on the Provisioning tab, the value is not encrypted, it should not be in the plain text. 

Actual results:
The root password is visible to any user. 

Expected results:
The root password should be in encrypted format. 

Additional info:
NA.

Comment 3 Suraj Patil 2020-06-01 06:39:57 UTC
Created redmine issue https://projects.theforeman.org/issues/29967 from this bug

Comment 4 Lukas Zapletal 2020-06-02 07:38:30 UTC
For the record, root password in Admister - Setting can be actually stored in Linux crypt format, that's the reason why it is not crypted. But we added possibility to accept it also via plaintext, then it needs to be crypted.

https://lukas.zapletalovi.com/2018/02/on-generating-kickstart-passwords.html

Comment 5 Bryan Kearney 2020-06-16 16:06:14 UTC
Moving this bug to POST for triage into Satellite 6 since the upstream issue https://projects.theforeman.org/issues/29967 has been resolved.

Comment 6 Brad Buckingham 2020-11-13 20:09:28 UTC
Fix is in Satellite 6.9 SNAP 1 with foreman-2.3.0-0.7.rc1.el7sat.noarch

Comment 7 Omkar Khatavkar 2020-11-30 07:51:05 UTC
Verified in Satellite 6.9 Snap 3, Issue is resolved now and not able to see the password in plaintext. Marking as verified.

Comment 10 errata-xmlrpc 2021-04-21 13:12:29 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Satellite 6.9 Release), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2021:1313


Note You need to log in before you can comment on or make changes to this bug.