Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-25551

Satellite's container list should return a 401 page except through LCEs that are configured for unauthenticated access

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • 0

      Satellite's container list shows result "{"repositories":[]}" when accessed over the URL "https://FQDN_or_IP/v2/_catalog" without authentication, but customer's security scanner reports that the correct result should be a 401 page.

      Since Satellite allows lifecycle environments to be configured to allow access without authentication, it seems reasonable to request that the Satellite server return a 401 page except when accessing that URL on hosts that are registered to lifecycle environments that have been manually configured to allow unauthenticated access.

              Unassigned Unassigned
              rhn-support-jrichards2 Jessica Richards
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: