Cookie hash value displayed in rabbitmq logs
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Invalid
|
Undecided
|
Unassigned | ||
OpenStack Security Notes |
New
|
Undecided
|
Unassigned |
Bug Description
ENabled rabbitmq debug and restarted the process. Found sensitive data displayed in logs.
rabbitmq uses Erlang cookie concept where a cluster of nodes communicates to each other. Any node that posses this secret cookie can communicate with other nodes in the cluster.
=INFO REPORT==== 31-Mar-
stopped SSL Listener on [::]:5671
=INFO REPORT==== 31-Mar-
Stopped RabbitMQ application
=INFO REPORT==== 31-Mar-
Halting Erlang VM
=INFO REPORT==== 31-Mar-
Starting RabbitMQ 3.6.6 on Erlang 19.1.1
Copyright (C) 2007-2016 Pivotal Software, Inc.
Licensed under the MPL. See http://
=INFO REPORT==== 31-Mar-
node : rabbit@
home dir : /var/lib/rabbitmq
config file(s) : /etc/rabbitmq/
cookie hash : RVLZk6qSkQ471Dq
log : /<email address hidden>
sasl log : /<email address hidden>
database dir : /var/lib/
=INFO REPORT==== 31-Mar-
Memory limit set to 3876MB of 9690MB total.
Archana, I believe the right place to open this bug is at https:/ /github. com/rabbitmq/ rabbitmq- server/ issues/ new as the logs mentioned here has nothing to do with Keystone.