From Fedora Project Wiki

(Created page with "== Mission == This project's mission is to eliminate the use of predictable passwords in LXC templates. It all started with [https://bugzilla.redhat.com/show_bug.cgi?id=11320...")
 
Line 6: Line 6:
== Templates ==
== Templates ==
The upstream templates are [https://github.com/lxc/lxc/tree/master/templates on Github].  Each template will be documented here as it's reviewed.
The upstream templates are [https://github.com/lxc/lxc/tree/master/templates on Github].  Each template will be documented here as it's reviewed.
{{admon/warning|Work in progress|This section is being updated regularly. --[[User:Mhayden|Mhayden]] ([[User talk:Mhayden|talk]]) 17:31, 18 June 2015 (UTC)}}
=== CentOS ===
No changes needed as randomized root passwords are already applied during build.
=== Debian ===
The upstream Debian template current sets root's password to <code>root</code>.  There's a [proposed fix https://github.com/major/lxc/commit/6982595560cc3b7e3b47d070c53161633e8a24dd] waiting on feedback from Debian's LXC package maintainer.


=== Fedora ===
=== Fedora ===
No changes needed as randomized root passwords are already applied during build.
No changes needed as randomized root passwords are already applied during build.


=== CentOS ===
=== Ubuntu ===
No changes needed as randomized root passwords are already applied during build.
The UBuntu template disables the root account but makes a regular user with sudo privileges that has <code>ubuntu</code> as a username and password (unless a user password is specified on the command line during build).


[[Category:Security]]
[[Category:Security]]

Revision as of 17:31, 18 June 2015

Mission

This project's mission is to eliminate the use of predictable passwords in LXC templates. It all started with BZ 1132001 which attached bug reports to fedora-all, EPEL 7, and EPEL 6. The problem exists upstream and the upstream developers are welcoming fixes.

This is part of the Fedora Security Team's 90-day challenge.

Templates

The upstream templates are on Github. Each template will be documented here as it's reviewed.

Warning.png
Work in progress
This section is being updated regularly. --Mhayden (talk) 17:31, 18 June 2015 (UTC)

CentOS

No changes needed as randomized root passwords are already applied during build.

Debian

The upstream Debian template current sets root's password to root. There's a [proposed fix https://github.com/major/lxc/commit/6982595560cc3b7e3b47d070c53161633e8a24dd] waiting on feedback from Debian's LXC package maintainer.

Fedora

No changes needed as randomized root passwords are already applied during build.

Ubuntu

The UBuntu template disables the root account but makes a regular user with sudo privileges that has ubuntu as a username and password (unless a user password is specified on the command line during build).