Uploaded image for project: 'RHEL Conversions'
  1. RHEL Conversions
  2. RHELC-703

Use dbus API for RHSM registration

    XMLWordPrintable

Details

    • 2022-Q3

    Description

      To resolve the CVE-2022-0851, we need to pass the activation key to subscription-manager in a different way than through the --activationkey CLI option as we do now. ptoscano@redhat.com from the subscription-manager team has suggested us to use the Subscription Manager dbus API.

      Note: We could use the dbus API later on for more things than just system registration, e.g. for listing available pool IDs.

      Acceptance criteria:

      • subscription-manager dbus API is used for registering the system instead of passing the activation key through the --activationkey CLI option
        • convert2rhel has a check that dbus is installed and running
      • measures are taken to avoid eavesdropping the registration credentials on the dbus
      • Test case shows that activation key is not visible from the process list

      Attachments

        Issue Links

          Activity

            People

              tkuratom@redhat.com Toshio Kuratomi
              mbocek@redhat.com Michal Bocek
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: