-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Configuration file /etc/tendrl/etcd.yml with etcd root password is readable for every account #293
Comments
Package |
@sidhax this seems like security related issue |
@mbukatov we don't have support for username and password based etcd auth anymore, is this still relevant? |
@anivargi that is true, the support for password authentication has been removed, but now I see an option to provide passphrase (I guess that it's a passphrase for the ssl private key, right?), so it seems to me that it is still relevant. |
tendrl-bug-id: Tendrl#293 Signed-off-by: Timothy Asir J <[email protected]>
tendrl-bug-id: #293 Signed-off-by: Timothy Asir J <[email protected]>
It is fixed now, We can close this. |
Description
Configuration file
/etc/tendrl/etcd.yml
can now contain username and password for etcd admin access, but the file is still packaged as world readable.Version
Latest snapshot build from master branch (it's part of upcoming 1.5.2 version):
Details
Details including reproducer, actual and expected results are similar to Tendrl/monitoring-integration#125, which you can refer to for more details:
The text was updated successfully, but these errors were encountered: