[openstack-dev] [Horizon] Blueprint for password decryption status

Alessandro Pilotti apilotti at cloudbasesolutions.com
Mon Mar 3 13:59:11 UTC 2014


Hi guys,

By checking the status of the patch at [1] by arezmerita, I noticed that it didn’t get any reviews since the last upload on Jan 31th (after a comprehensive round of reviews started on Dec 10th).

During a chat on #openstack-horizon, jpich noticed that the BP [2] was not targetted, so it didn’t get on the radar for any milestone. The milestone has now been set to Icehouce.

I know that it’s really late for I3, but since the patch has already been reviewed and all the concerns / suggestions have been addressed, I wonder if this could still be considered for merging.


The blueprint addresses a fundamental issue for Windows guests VMs: handling passwords in a secure way.

Password encryption is a feature that is present in Nova since Grizzly (see "nova get-password" [3]), but most users are still using the totally unsafe clear text “admin_pass" option for the
simple reason that the dashboard does not provide a way to manage password decryption.

Ala’s patch provides IMO a proper solution for this issue, so it’d be great if we could have it in Icehouse, whithout having to wait for Juno.


Thanks,

Alessandro

P.S.: Note: I’m not the owner of the patch or the blueprint.

[1] https://review.openstack.org/#/c/61032/
[2] https://blueprints.launchpad.net/horizon/+spec/decrypt-and-display-vm-generated-password
[3] http://docs.openstack.org/user-guide/content/novaclient_commands.html





-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20140303/241fbe4b/attachment.html>


More information about the OpenStack-dev mailing list