Expose ENFORCE_PASSWORD_CHECK option in charm configuration, defaulting to true

Bug #1883196 reported by James Hebden
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Dashboard Charm
Fix Released
Wishlist
Unassigned

Bug Description

The OpenStack security guide [0] suggests that ENFORCE_PASSWORD_CHECK be enabled to aid in verifying the identity of an administrative user when resetting passwords, as a mechanism for mitigating the impact of dashboard session hijacking.

The ENFORCE_PASSWORD_CHECK makes sure the user enters their password when resetting passwords, and should be set to true by default. It is currently commented out in the template, and set to false in the commented out example - this value will need to be templated and exposed via charm configuration.

Tags: onboarding
Changed in charm-openstack-dashboard:
status: New → Triaged
importance: Undecided → Wishlist
tags: added: onboarding
Changed in charm-openstack-dashboard:
assignee: nobody → Garrett Thompson (thogarre)
status: Triaged → In Progress
Revision history for this message
Garrett Neugent (thogarre) wrote :

Here's the missing link in James' original report [0], which is the security guide's recommendation that this be enabled by default:

https://docs.openstack.org/security-guide/dashboard/checklist.html#check-dashboard-09-is-enforce-password-check-set-to-true

Revision history for this message
Garrett Neugent (thogarre) wrote :
Changed in charm-openstack-dashboard:
assignee: Garrett Thompson (thogarre) → nobody
status: In Progress → Fix Committed
Changed in charm-openstack-dashboard:
milestone: none → 21.04
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.