Bug 718226 - Guests built for VMware allow ssh as root with default password
Summary: Guests built for VMware allow ssh as root with default password
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: CloudForms Cloud Engine
Classification: Retired
Component: imagefactory
Version: 1.0.0
Hardware: Unspecified
OS: Unspecified
medium
high
Target Milestone: rc
Assignee: Ian McLeod
QA Contact: wes hayutin
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-07-01 13:57 UTC by Matt Wagner
Modified: 2014-08-17 22:27 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 719377 (view as bug list)
Environment:
Last Closed: 2012-05-15 20:08:05 UTC


Attachments (Terms of Use)
ss - blank passwd (5.56 KB, image/png)
2011-11-07 18:11 UTC, wes hayutin
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2012:0588 0 normal SHIPPED_LIVE new packages: imagefactory 2012-05-15 22:31:27 UTC

Description Matt Wagner 2011-07-01 13:57:25 UTC
Description of problem:
I've just coerced a guest to build and launch on vSphere. No ssh keypair is present, and I was able to ssh in as root with the default 'ozrootpw' password. In theory the user can override this in the template, but if they don't, minting VM images with a predictable root password will be a security risk.


Version-Release number of selected component (if applicable):
imagefactory-0.2.2-1.el6.noarch

How reproducible:
100%

Expected results:
Guests are not launched with a publicly-known root password.

Comment 1 Chris Lalancette 2011-07-01 15:46:48 UTC
So the thing is that Oz already has the ability to set the root password at build time, via the <rootpw> tag (see the RelaxNG schema for the right placement).  I'm thinking that we should "enforce" this tag at the imagefactory level by not accepting builds unless they have this tag set.  That will at least make sure that builds coming from the factory aren't insecure by default.

Chris Lalancette

Comment 2 wes hayutin 2011-07-06 16:02:46 UTC
sounds like a doc issue for beta release notes

Comment 3 wes hayutin 2011-09-28 16:38:18 UTC
making sure all the bugs are at the right version for future queries

Comment 6 wes hayutin 2011-11-07 18:11:45 UTC
Created attachment 532113 [details]
ss - blank passwd

screen shot of blank passwd in template description.
I'm assuming that is ok

[root@qeblade30 ~]# rpm -qa | grep imagefactory
rubygem-imagefactory-console-0.5.0-4.20110824113238gitd9debef.el6.noarch
imagefactory-jeosconf-ec2-rhel-0.8.0-1.el6.noarch
imagefactory-jeosconf-ec2-fedora-0.8.0-1.el6.noarch
imagefactory-0.8.0-1.el6.noarch
[root@qeblade30 ~]#

Comment 8 errata-xmlrpc 2012-05-15 20:08:05 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2012-0588.html


Note You need to log in before you can comment on or make changes to this bug.