Public bug reported: Using current KA (12.2.0), deploying Wallaby, i'm seeing Nova not set instance passwords unless its done via user_data directives. The default password in our Windows images is never changed, even if explicitly told to during instance creation. Same thing for Linux & BSD, regardless of whether the username is set in the image metadata properties or not. I've reported the same issue to the Juju tracker (was using their stack until snaps killed a cloud), no answer from them yet. This _may_ be considered a security issue as it removes the function of wiping static default credentials pre-baked into images (https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password).
This was previously filed as https://bugs.launchpad.net/bugs/1942654 under kolla-ansible ** Affects: nova Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1949674 Title: Nova Doesn't Set Instance Passwords Status in OpenStack Compute (nova): New Bug description: Using current KA (12.2.0), deploying Wallaby, i'm seeing Nova not set instance passwords unless its done via user_data directives. The default password in our Windows images is never changed, even if explicitly told to during instance creation. Same thing for Linux & BSD, regardless of whether the username is set in the image metadata properties or not. I've reported the same issue to the Juju tracker (was using their stack until snaps killed a cloud), no answer from them yet. This _may_ be considered a security issue as it removes the function of wiping static default credentials pre-baked into images (https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password). This was previously filed as https://bugs.launchpad.net/bugs/1942654 under kolla-ansible To manage notifications about this bug go to: https://bugs.launchpad.net/nova/+bug/1949674/+subscriptions -- Mailing list: https://launchpad.net/~yahoo-eng-team Post to : [email protected] Unsubscribe : https://launchpad.net/~yahoo-eng-team More help : https://help.launchpad.net/ListHelp

