Bug 475190 - sos modifes ldap.conf
Summary: sos modifes ldap.conf
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: sos
Version: 5.4
Hardware: All
OS: Linux
low
high
Target Milestone: rc
: ---
Assignee: Adam Stokes
QA Contact: BaseOS QE
URL:
Whiteboard:
Depends On: 444714
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-12-08 13:15 UTC by Adam Stokes
Modified: 2018-10-27 11:26 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
For security reasons, sos sanitizes passwords that would otherwise appear in its report, including the shared secret (bindpw) from /etc/ldap.conf. Previously, if /etc/openldap/ldap.conf were symbolically linked to /etc/ldap.conf, sos would sanitize the bindpw in ldap.conf itself. Now, sos only sanitises the bindpw that is included in its report.
Clone Of:
Environment:
Last Closed: 2009-09-02 07:31:21 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2009:1418 0 normal SHIPPED_LIVE sos bug fix and enhancement update 2009-09-02 07:29:42 UTC

Comment 4 Chris Ward 2009-07-03 18:15:51 UTC
~~ Attention - RHEL 5.4 Beta Released! ~~

RHEL 5.4 Beta has been released! There should be a fix present in the Beta release that addresses this particular request. Please test and report back results here, at your earliest convenience. RHEL 5.4 General Availability release is just around the corner!

If you encounter any issues while testing Beta, please describe the issues you have encountered and set the bug into NEED_INFO. If you encounter new issues, please clone this bug to open a new issue and request it be reviewed for inclusion in RHEL 5.4 or a later update, if it is not of urgent severity.

Please do not flip the bug status to VERIFIED. Only post your verification results, and if available, update Verified field with the appropriate value.

Questions can be posted to this bug or your customer or partner representative.

Comment 7 Ruediger Landmann 2009-09-02 01:38:54 UTC
Release note added. If any revisions are required, please set the 
"requires_release_notes" flag to "?" and edit the "Release Notes" field accordingly.
All revisions will be proofread by the Engineering Content Services team.

New Contents:
For security reasons, sos sanitizes passwords that would otherwise appear in its report, including the shared secret (bindpw) from /etc/ldap.conf. Previously, if /etc/openldap/ldap.conf were symbolically linked to /etc/ldap.conf, sos would sanitize the bindpw in ldap.conf itself. Now, sos only sanitises the bindpw that is included in its report.

Comment 8 errata-xmlrpc 2009-09-02 07:31:21 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2009-1418.html


Note You need to log in before you can comment on or make changes to this bug.