[Openstack-security] [Bug 1188189] Fix merged to keystone (master)

OpenStack Infra 1188189 at bugs.launchpad.net
Mon Mar 17 22:01:22 UTC 2014


Reviewed:  https://review.openstack.org/76476
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=5bd4c2984d329625a2a8442b316fa235dbb88a3d
Submitter: Jenkins
Branch:    master

commit 5bd4c2984d329625a2a8442b316fa235dbb88a3d
Author: Daniel Gollub <d.gollub at telekom.de>
Date:   Wed Feb 26 06:56:13 2014 +0100

    Replace httplib.HTTPSConnection in ec2_token
    
    httplib.HTTPSConnection is known to not verify SSL certificates in Python 2.x.
    Implementation got adapted to make use of the requests module instead.
    
    SSL Verification is from now on enabled by default.
    
    Can be disabled via an additional introduced configuration option:
    
    `keystone_ec2_insecure=True`
    
    SecurityImpact
    DocImpact
    Partial-Bug: 1188189
    
    Change-Id: Ie6a6620685995add56f38dc34c9a0a733558146a

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1188189

Title:
  Some server-side 'SSL' communication fails to check certificates (use
  of HTTPSConnection)

Status in Cinder:
  In Progress
Status in OpenStack Identity (Keystone):
  In Progress
Status in OpenStack Neutron (virtual network service):
  In Progress
Status in OpenStack Compute (Nova):
  Confirmed
Status in OpenStack Security Advisories:
  Won't Fix
Status in OpenStack Security Notes:
  Fix Released
Status in Python client library for Keystone:
  Fix Released
Status in OpenStack Object Storage (Swift):
  Invalid

Bug description:
  Grant Murphy from Red Hat reported usage of httplib.HTTPSConnection
  objects. In Python 2.x those do not perform CA checks so client
  connections are vulnerable to MiM attacks.

  """
  The following files use httplib.HTTPSConnection :
  keystone/middleware/s3_token.py
  keystone/middleware/ec2_token.py
  keystone/common/bufferedhttp.py
  vendor/python-keystoneclient-master/keystoneclient/middleware/auth_token.py

  AFAICT HTTPSConnection does not validate server certificates and
  should be avoided. This is fixed in Python 3, however in 2.X no
  validation occurs. I suspect this is also applicable to most OpenStack
  modules that make HTTPS client calls.

  Similar problems were found in ovirt:
  https://bugzilla.redhat.com/show_bug.cgi?id=851672 (CVE-2012-3533)

  With solutions for ovirt:
  http://gerrit.ovirt.org/#/c/7209/
  http://gerrit.ovirt.org/#/c/7249/
  """

To manage notifications about this bug go to:
https://bugs.launchpad.net/cinder/+bug/1188189/+subscriptions




More information about the Openstack-security mailing list