[Openstack-security] [openstack/nova] SecurityImpact review request change I0b8e6319a4cc39876b1e396ef705f0fc5def1e44
gerrit2 at review.openstack.org
gerrit2 at review.openstack.org
Thu Nov 20 09:48:40 UTC 2014
Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/127203
Log:
commit 164805ab0c9ad103d42fd2d123c48388494a0272
Author: Sylvain Bauza <sbauza at redhat.com>
Date: Mon Sep 29 13:33:50 2014 +0200
Fix unsafe SSL connection on TrustedFilter
TrustedFilter was using httplib which doesn't check for CAs.
Here the change is using Requests and verifies local CAs by default (or another
one if provided)
This effort is related to CVE 2013-2255.
This patch changes new added option attestation_insecure_ssl default value
from false to true to disable SSL cert verification for Attestation service,
to ensure there is no compatibility issue with prior release.
SecurityImpact
Closes-Bug: #1373993
(cherry picked from commit 30871e8702737edbbfbcbbb5f21858873b37685c)
Conflicts:
nova/tests/scheduler/test_host_filters.py
Change-Id: I0b8e6319a4cc39876b1e396ef705f0fc5def1e44
More information about the Openstack-security
mailing list