yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #89210
[Bug 1949674] Re: Nova Doesn't Set Instance Passwords
[Expired for OpenStack Compute (nova) because there has been no activity
for 60 days.]
** Changed in: nova
Status: Incomplete => Expired
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1949674
Title:
Nova Doesn't Set Instance Passwords
Status in OpenStack Compute (nova):
Expired
Bug description:
Using current KA (12.2.0), deploying Wallaby, i'm seeing Nova not set instance passwords unless its done via user_data directives. The default password in our Windows images is never changed, even if explicitly told to during instance creation. Same thing for Linux & BSD, regardless of whether the username is set in the image metadata properties or not.
I've reported the same issue to the Juju tracker (was using their stack until snaps killed a cloud), no answer from them yet.
This _may_ be considered a security issue as it removes the function of wiping static default credentials pre-baked into images (https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password).
This was previously filed as https://bugs.launchpad.net/bugs/1942654
under kolla-ansible
To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1949674/+subscriptions
References