Modify

Opened 7 years ago

Closed 7 years ago

#52 closed enhancement (fixed)

Root Password Initialisation

Reported by: mglb1 Owned by: mglb1
Priority: major Milestone: Rural Link Farm Networks Product Launch
Component: pxe-scripts Version: HEAD
Keywords: Cc:
Estimated Hours Work: 6

Description

The rurallink pxe boot scripts need to be extended to generate and set the root password on each rurallink device.

The root password will be set to

md5(eth0mac + master_password)[-8:]

This means that we can give out the root password for a specific device without compromising the security of other devices.

If the master password is compromised and the above algorithm is known then all devices are compromised. However this password is only useful via serial as SSH only allows logins with a public key, so the failure case of the master_password being compromised is not too severe.

Password generation will be handled inside the Configuration System Daemon so that the master password is not stored with the pxe-scripts. When given a MAC address a password will be returned, this ensures that the master password is not inadvertantly disclosed.

Attachments (0)

Change History (1)

comment:1 Changed 7 years ago by mglb1

  • Resolution set to fixed
  • Status changed from new to closed

Implemented in version 11 of the pxe-scripts package

Add Comment

Modify Ticket

Change Properties
<Author field>
Action
as closed .
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.