• Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.21
    • MicroShift
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • 0
    • None
    • None
    • None
    • None
    • uShift Sprint 284
    • 1
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      MicroShift's apiserver explicitly allow anonymous auth. Even if anonymous users do not have any RBAC permissions, and can therefore do nothing, this is considered to be a security flaw.
      
      Anonymous auth is used for readiness checks when starting MicroShift, but kubeconfigs already exist by then, so it could use authenticated queries to the health endpoint.

      Version-Release number of selected component (if applicable):

      4.21

      How reproducible:

      100%

      Steps to Reproduce:

      1.
      2.
      3.
      

      Actual results:

       

      Expected results:

       

      Additional info:

       

              pacevedo@redhat.com Pablo Acevedo Montserrat
              pacevedo@redhat.com Pablo Acevedo Montserrat
              None
              None
              John George John George
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: