add release note that OpenStack should be used on a protected network

Bug #978961 reported by Jamie Strandboge
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
horizon (Ubuntu)
Triaged
High
Unassigned
Precise
Triaged
High
Unassigned
keystone (Ubuntu)
Triaged
High
Unassigned
Precise
Triaged
High
Unassigned

Bug Description

Much of OpenStack is hard-coded to use http instead of https. Of particular interest is keystone which is the identity service for OpenStack. https://wiki.ubuntu.com/PrecisePangolin/ReleaseNotes/UbuntuCloud should state that accessing OpenStack over an unprotected network may expose credentials and other information. This is true (at least) when:
* keystone is on a separate server from the other OpenStack components
* horizon (the OpenStack Dashboard) is on a different system than keystone
* users access OpenStack remotely

Adding horizon and keystone tasks.

Changed in keystone (Ubuntu Precise):
status: New → Triaged
Changed in horizon (Ubuntu Precise):
status: New → Triaged
Changed in keystone (Ubuntu Precise):
importance: Undecided → High
Changed in horizon (Ubuntu Precise):
importance: Undecided → High
Changed in keystone (Ubuntu Precise):
milestone: none → ubuntu-12.04
Changed in horizon (Ubuntu Precise):
milestone: none → ubuntu-12.04
tags: added: rls-p-tracking
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.