Public bug reported:

[ Impact ]

When doing SRU for sos 4.8.2 we encountered obfuscation issues, although
not a regression at the time, it was still an issue that had been
present for a while

1. So, these passwords would be fully visible to the end support personnel and 
therefore leaked passwords.
2. Some logs had not longer being collected which are essential for debugging, 
such as auth.log, syslog and kern.log in /var/log
3. The ubuntu plugin was no longer collecting Ubuntu Pro details due to the 
package name for ubuntu-pro, and hence essential for supportability for 
customers that have Ubuntu Pro

[ Test Plan ]

Test 1. Deploy a openstack simple cloud, and run the sos report, check
to see if passwords are obfuscated in configuration file for radosgw and
horizon config in particular /etc/ceph/ceph.conf and
/etc/horizon/local_settings.py

Test 2. Deploy all series, and ensure the the auth.log, syslog and kerne.log 
are collected from /var/log.
Test 3. On the same hosts as Test 2, ensure that /var/log/ubuntu-advantage logs 
are collected


[ Where problems could occur ]

1. The corresponding files are not obfuscated, and we need to update the 
patches.
2. The files that have been specified are not being collected.

** Affects: sos (Ubuntu)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: In Progress

** Affects: sosreport (Ubuntu Focal)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: Confirmed

** Affects: sosreport (Ubuntu Jammy)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: Confirmed

** Affects: sosreport (Ubuntu Noble)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: Confirmed

** Affects: sosreport (Ubuntu Oracular)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: Confirmed

** Affects: sos (Ubuntu Plucky)
     Importance: Undecided
     Assignee: Arif Ali (arif-ali)
         Status: In Progress

** Also affects: sosreport (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: sosreport (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Also affects: sosreport (Ubuntu Plucky)
   Importance: Undecided
       Status: New

** Also affects: sosreport (Ubuntu Focal)
   Importance: Undecided
       Status: New

** Also affects: sosreport (Ubuntu Oracular)
   Importance: Undecided
       Status: New

** No longer affects: sosreport (Ubuntu Plucky)

** No longer affects: sosreport (Ubuntu)

** Also affects: sos (Ubuntu)
   Importance: Undecided
       Status: New

** No longer affects: sos (Ubuntu Focal)

** No longer affects: sos (Ubuntu Jammy)

** No longer affects: sos (Ubuntu Noble)

** No longer affects: sos (Ubuntu Oracular)

** Also affects: sos (Ubuntu Plucky)
   Importance: Undecided
       Status: New

** Changed in: sos (Ubuntu Plucky)
     Assignee: (unassigned) => Arif Ali (arif-ali)

** Changed in: sos (Ubuntu Plucky)
       Status: New => In Progress

** Changed in: sosreport (Ubuntu Focal)
       Status: New => Confirmed

** Changed in: sosreport (Ubuntu Jammy)
       Status: New => Confirmed

** Changed in: sosreport (Ubuntu Noble)
       Status: New => Confirmed

** Changed in: sosreport (Ubuntu Oracular)
       Status: New => Confirmed

** Changed in: sosreport (Ubuntu Jammy)
     Assignee: (unassigned) => Arif Ali (arif-ali)

** Changed in: sosreport (Ubuntu Noble)
     Assignee: (unassigned) => Arif Ali (arif-ali)

** Changed in: sosreport (Ubuntu Focal)
     Assignee: (unassigned) => Arif Ali (arif-ali)

** Changed in: sosreport (Ubuntu Oracular)
     Assignee: (unassigned) => Arif Ali (arif-ali)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2101134

Title:
  [sru] Obfuscation issues in sosreport sos 4.8.2

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sos/+bug/2101134/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to