Repository navigation
fix(roles): keep the Icinga API credentials away from local users - #420
Open
NavidSassan wants to merge 7 commits into
Open
NavidSassan wants to merge 7 commits into
NavidSassan wants to merge 7 commits into
Conversation
The filter had a stray quote before the second match() and the body a trailing comma, so the Icinga API answered 400 and borg-backup, which runs curl with --silent and discards the output, never set the downtime (verified against Icinga 2.14.6: 400 before, 200 now).
…l users borg-backup was deployed 0755 and passed the credentials to curl with --user. It is now 0700, since only root runs it (systemd timers), and the credentials reach curl as a header read from a pipe that the printf builtin fills.
…cal users do-reboot was deployed 0744 and passed the Icinga API credentials with --user and the Rocket.Chat webhook URL, which carries its token, as curl arguments. It is now 0700, since only schedule-reboot.service runs it, the credentials reach curl as a header from a pipe, and the URL through --config <(printf ...), verified with curl 7.61.1 on Rocky 8. The Molecule reboot scenario still sees the same Authorization header.
schedule-icinga-downtime was a shell function in /etc/profile.d/alias.sh, which every login shell reads, so every local user could read the credentials and set downtimes with them. It is now /usr/local/sbin/schedule-icinga-downtime, readable and executable by root only, which the reboot alias calls through root's PATH. The function also ran `exit 1` on a missing argument, which closed the calling shell. Verified on Rocky 10: the script sets the downtime for the host and all its services on Icinga 2.14.6, and strace shows the password in no execve argument.
…o root Set tools__icinga2_api_* so that schedule-icinga-downtime gets deployed. Assert that it is 0700 root, and that a login shell of nobody sees the reboot alias but not the password, and cannot run the script.
Member
Author
MoleculeLatest VM per distro, ansible-core 2.16:
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Extracted from #396, which it does not depend on.
The password of the Icinga API user was readable by every local user on hosts deployed with
setup_basic, andborg-backupanddo-rebootpassed it to curl on the command line, where it shows up in the process list. The Rocket.Chat webhook ofschedule_reboot, which carries its token, had the same problem.Changes
schedule-icinga-downtimemoves from a shell function in/etc/profile.d/alias.sh, which every login shell sources, to/usr/local/sbin/schedule-icinga-downtime, mode 0700. Therebootalias calls it through root's PATH. The function also ranexit 1on a missing argument, which closed the calling shell.borg-backupis 0700 instead of 0755, and curl reads the credentials as a header from a pipe that theprintfbuiltin fills instead of getting them with--user. Theclamd@scandowntime request had a stray quote and a trailing comma, so Icinga answered 400 and the downtime was never set.do-rebootis 0700 instead of 0744. The credentials reach curl the same way, the webhook URL through--config <(printf ...).do-rebootis 0700 root.schedule-icinga-downtimeand asserts it is 0700 root, and that a login shell ofnobodysees therebootalias but neither the password nor a working script.Admins who ran
schedule-icinga-downtimeas an unprivileged user need root now.Tests
execveargument, theclamd@scanrequest returns 200 instead of 400.--header @fileand--configverified with curl 7.61.1 on Rocky 8.schedule_reboot/no_rebootandsetup_basichave not been run on this branch yet.