Project

General

Profile

Actions

Bug #9841

closed

Bootstrap log contains validation.pem

Added by Marek Hulán about 9 years ago. Updated almost 9 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
Category:
foreman_chef
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

We keep /tmp/bootstrap-* file with log of finish provisioning template which may contain validation.pem (a private key for the node). Unfortunately, it's world readable.

Actions #1

Updated by Marek Hulán almost 9 years ago

  • Status changed from New to Rejected
  • Assignee set to Marek Hulán

It's only in script file itself which can be read only by root. 0701 mode is being set since 1.3 (when ssh orchestration was introduced).

Actions #2

Updated by Marek Hulán almost 9 years ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF