Menu

#95 ipmiusr default account secure

v1.0_(example)
closed-fixed
nobody
None
5
2022-07-07
2022-07-06
hexing
No

/etc/ipmi/lan.conf has a default cleartext account ipmiusr, if I don't configure the user, will he have this account by default, is there a security risk?
​lan.conf permission is 644, ordinary users can also see, is not the risk of leaking the password?

Discussion

  • Corey Minyard

    Corey Minyard - 2022-07-07
    • status: open --> closed-fixed
     
  • Corey Minyard

    Corey Minyard - 2022-07-07

    You are right, I've adjusted the permissions to be 600 for the installed config file.

     
  • Corey Minyard

    Corey Minyard - 2022-07-07

    On Wed, Jul 06, 2022 at 02:19:50AM -0000, hexing wrote:

    /etc/ipmi/lan.conf has a default cleartext account ipmiusr, if I don't configure the user, will he have this account by default, is there a security risk?
    ​lan.conf permission is 644, ordinary users can also see, is not the risk of leaking the password?

    Yes, you are right to worry about this. If you are using ipmi_sim in a
    production system, yes, lan.conf should be 600 permissions. I've
    modified the makefile to install them 600.

    Thanks,

    -corey

     

Log in to post a comment.

MongoDB Logo MongoDB