-
Bug
-
Resolution: Done
-
None
-
6.4
-
None
Description of problem:
Client (FDIC) is requesting bootstrap.py have capability restored/added to invoke without username and password. An activation key should suffice.
Security finding is due to recent insider pen test that showed:
- appearance of plaintext usernames and password in command histories
- appearance of plaintext username and password in BixFix invocation of bootstrap.py (BigFix must allow a wider set of users such as Windows admins, than are normally given Sat admin, which violates separation of duties)
Requesting the ability to specify an activation key only, and allow all the Host Group and Foreman creation activities to be triggered internally on the Satellite side.