[Openstack-security] [Bug 1579914] [NEW] Security role doesn't handle sshd_config with Match

Major Hayden major at mhtx.net
Mon May 9 20:54:42 UTC 2016


Public bug reported:

The security role makes several changes to the sshd_config file, but it
doesn't handle situations where the configuration file might end with
Match stanzas.  There cannot be any general configuration options after
any Match stanzas in the configuration file.

The role should:

 * Handle Match stanzas properly
 * Validate the sshd_config with each change

** Affects: openstack-ansible
     Importance: Undecided
     Assignee: Major Hayden (rackerhacker)
         Status: New


** Tags: security

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1579914

Title:
  Security role doesn't handle sshd_config with Match

Status in openstack-ansible:
  New

Bug description:
  The security role makes several changes to the sshd_config file, but
  it doesn't handle situations where the configuration file might end
  with Match stanzas.  There cannot be any general configuration options
  after any Match stanzas in the configuration file.

  The role should:

   * Handle Match stanzas properly
   * Validate the sshd_config with each change

To manage notifications about this bug go to:
https://bugs.launchpad.net/openstack-ansible/+bug/1579914/+subscriptions




More information about the Openstack-security mailing list