[Openstack-security] [Bug 1451931] Re: ironic password config not marked as secret

Nathan Kinder nkinder at redhat.com
Mon Nov 16 21:37:15 UTC 2015


This has been published as OSSN-0049:

  https://wiki.openstack.org/wiki/OSSN/OSSN-0049

** Changed in: ossn
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1451931

Title:
  ironic password config not marked as secret

Status in OpenStack Compute (nova):
  Fix Released
Status in OpenStack Compute (nova) juno series:
  Fix Committed
Status in OpenStack Compute (nova) kilo series:
  Fix Released
Status in OpenStack Security Advisory:
  Won't Fix
Status in OpenStack Security Notes:
  Fix Released

Bug description:
  The ironic config option for the password and auth token are not
  marked as secret so the values will get logged during startup in debug
  mode.

To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1451931/+subscriptions




More information about the Openstack-security mailing list