Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove rule package_telnet_removed from profiles in rhel7, rhel8, rhv4 #4958

Conversation

vojtapolasek
Copy link
Collaborator

@vojtapolasek vojtapolasek commented Oct 31, 2019

Description:

The rule package_telnet_removed was removet from all profiles shipped with rhel7, rhel8 and rhv4

Rationale:

Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1729222

The rule package_telnet_removed removes Telnet client which is needed by some installations, especially fence agents. The Telnet server, which introduces much bigger security problem, is removed by a different rule. It should be fine to keep the Telnet client as it does not introduce direct security risk.

@yuumasato
Copy link
Member

yuumasato commented Oct 31, 2019

I wonder if other Profiles should drop the rule package_telnet_removed as well.

@vojtapolasek vojtapolasek changed the title remove rule package_telnet_removed from ncp rhel7 profile remove rule package_telnet_removed from profiles in rhel7, rhel8, rhv4 Oct 31, 2019
@vojtapolasek vojtapolasek changed the base branch from master to stabilization-v0.1.47 October 31, 2019 16:00
@redhatrises
Copy link
Contributor

redhatrises commented Oct 31, 2019

This is a NACK. Any use of telnet whether client or server brings unencrypted remote authentication and is a huge problem.

@yuumasato
Copy link
Member

Any use of telnet whether client or server brings unencrypted remote authentication and is a huge problem.

@redhatrises Note it is just removing rule for the "client removed", any rule for server removed is preserved.

Can you clarify what is the problematic use case with the telnet client installed?

@vojtapolasek
Copy link
Collaborator Author

Just to clarify why I am suggesting this, telnet is a dependency of several fence agents, to be exact 11 packages in rhel7 and 10 packages in rhel8.

@redhatrises
Copy link
Contributor

Any use of telnet whether client or server brings unencrypted remote authentication and is a huge problem.

@redhatrises Note it is just removing rule for the "client removed", any rule for server removed is preserved.

Can you clarify what is the problematic use case with the telnet client installed?

The problem is that it initiates an unencrypted remote session which can pass username and password in the clear. The fence agents a part of layered products need to start following good security practices as well now which means they need to start removing telnet functionality.

@redhatrises
Copy link
Contributor

Closing. See Steve Grubb's added comments about this https://lists.fedorahosted.org/archives/list/scap-security-guide@lists.fedorahosted.org/message/CYAR26WBNZIZHIO76LNKQINORX3UPWL7/

@redhatrises redhatrises closed this Nov 6, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants