cloudstack-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Wido den Hollander (JIRA)" <j...@apache.org>
Subject [jira] [Closed] (CLOUDSTACK-7537) RBD pool secret should be masked in logs
Date Thu, 16 Jul 2015 14:20:05 GMT

     [ https://issues.apache.org/jira/browse/CLOUDSTACK-7537?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Wido den Hollander closed CLOUDSTACK-7537.
------------------------------------------
    Resolution: Fixed

Closing this one for now since the logging ONLY happens when running in DEBUG mode.

We should fix that we shouldn't always run in DEBUG mode.

> RBD pool secret should be masked in logs
> ----------------------------------------
>
>                 Key: CLOUDSTACK-7537
>                 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-7537
>             Project: CloudStack
>          Issue Type: Bug
>      Security Level: Public(Anyone can view this level - this is the default.) 
>    Affects Versions: 4.2.0
>            Reporter: Kishan Kavala
>
> RBD pool authentication secret key is logged in plain text in management server and agent
logs at the following places:
> - While adding pool to MS
> - When MS send modifyStorage pool command to agent
> secret should not be visible in plain text.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message