[openstack-dev] Service password storage

2016-01-11 Thread Levin
Dear openstack developers, I installed openstack via devstack recently, and I found out that the admin passwords for services like cinder and nova are stored in plain text in their /etc/*/*.conf files. These files are rw--r--r-- by default, which I believe to be a pretty serious security risk. Is

Re: [openstack-dev] Service password storage

2016-01-11 Thread Clint Byrum
Excerpts from Levin's message of 2016-01-11 02:37:09 -0800: > Dear openstack developers, > I installed openstack via devstack recently, and I found out that the > admin passwords for services like cinder and nova are stored in plain > text in their /etc/*/*.conf files. These files are rw--r--r--

Re: [openstack-dev] Service password storage

2016-01-11 Thread Jeremy Stanley
On 2016-01-11 11:37:09 +0100 (+0100), Levin wrote: > I installed openstack via devstack recently, and I found out that the > admin passwords for services like cinder and nova are stored in plain > text in their /etc/*/*.conf files. These files are rw--r--r-- by > default, which I believe to be a