[Openstack] [OSSG] Security Note: Selecting LXC as Nova Virtualization Driver can lead to data compromise.

2013-03-15 Thread Clark, Robert Graham
The following is the first of a series of OpenStack Security Notes that will be issued by the OpenStack Security Group. Security notes are similar to advisories; they address vulnerabilities in 3rd party tools typically used within OpenStack deployments and provide guidance on common configurati

Re: [Openstack] [OSSG] Security Note: Selecting LXC as Nova Virtualization Driver can lead to data compromise.

2013-03-19 Thread Clark, Robert Graham
Daniel, I agree with your modification and have made a note of it on the bug page. I'll make sure to change it when we have a sensible place to publish all of our OSSNs. Thanks for engaging on this issue, we now have an OSSG mailing list and will be ramping up a number of efforts on there, having

Re: [Openstack] [OSSG] Security Note: Selecting LXC as Nova Virtualization Driver can lead to data compromise.

2013-03-19 Thread Clark, Robert Graham
It's literally just been allocated, I'll send round the details as soon as I've got that far down my todo list ;) > -Original Message- > From: Daniel P. Berrange [mailto:berra...@redhat.com] > Sent: 19 March 2013 13:42 > To: Clark, Robert Graham > Cc: Bry

[Openstack] [OSSG][OSSN] HTTP POST limiting advised to avoid Essex/Folsom Keystone DoS

2013-04-23 Thread Clark, Robert Graham
HTTP POST limiting advised to avoid Essex/Folsom Keystone DoS --- ### Summary ### Concurrent Keystone POST requests with large body messages are held in memory without filtering or rate limiting, this can lead to resource exhaustion on the Keystone server. ### Affected Services / Software ### K

[Openstack] [OSSG][OSSN] Keystone configuration should not be world readable.

2013-05-13 Thread Clark, Robert Graham
Keystone configuration should not be world readable --- ### Summary ### In some deployments keystone.conf which contains confidential information, is set to world readable. ### Affected Services / Software ### Keystone, DevStack, Deployment ### Discussion ### It is important that deployers of O

[Openstack] [OSSN][OSSG] Nova Baremetal Exposes Previous Tenant Data

2013-07-02 Thread Clark, Robert Graham
Nova Baremetal Exposes Previous Tenant Data - ### Summary ### Data of previous tenants may be exposed to new ones when using Nova Baremetal ### Affected Services / Software ### Keystone, Databases ### Discussion ### Nova Baremetal is intended for testing and development only, it is not inten

[Openstack] [OSSN] [OSSG] Nova Baremetal Exposes Previous Tenant Data

2013-07-03 Thread Clark, Robert Graham
Nova Baremetal Exposes Previous Tenant Data - ### Summary ### Data of previous tenants may be exposed to new ones when using Nova Baremetal ### Affected Services / Software ### Keystone, Databases ### Discussion ### Nova Baremetal is intended for testing and development only, it is not inten