[openstack-dev] Service password storage

Levin irrenhaus3 at gmail.com
Mon Jan 11 10:37:09 UTC 2016

Dear openstack developers,
I installed openstack via devstack recently, and I found out that the
admin passwords for services like cinder and nova are stored in plain
text in their /etc/*/*.conf files. These files are rw--r--r-- by
default, which I believe to be a pretty serious security risk. Is this
intended, and/or configurable pre-install?


More information about the OpenStack-dev mailing list