<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 19:08:22 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[AAA-1] Default admin credentials are very dangerous from a security perspective</title>
                <link>https://jira.opendaylight.org/browse/AAA-1</link>
                <project id="10102" key="AAA">aaa</project>
                    <description>&lt;p&gt;Opendaylight has default admin credentials (admin/admin). This is dangerous from a security perspective, as many users will never change the defaults. Users should be prompted to set the default admin password at install time.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: Linux&lt;br/&gt;
Platform: PC&lt;/p&gt;</environment>
        <key id="22252">AAA-1</key>
            <summary>Default admin credentials are very dangerous from a security perspective</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10001">Won&apos;t Do</resolution>
                                        <assignee username="-1">Unassigned</assignee>
                                    <reporter username="djorm@iix.net">David Jorm</reporter>
                        <labels>
                    </labels>
                <created>Mon, 7 Apr 2014 03:48:14 +0000</created>
                <updated>Thu, 21 Mar 2019 11:56:49 +0000</updated>
                            <resolved>Wed, 16 Dec 2015 16:43:14 +0000</resolved>
                                                                    <component>General</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                                                                <comments>
                            <comment id="42113" author="tony.tkacik@gmail.com" created="Tue, 26 May 2015 16:23:01 +0000"  >&lt;p&gt;Moving to aaa, since config uses aaa for credentials management.&lt;/p&gt;</comment>
                            <comment id="42114" author="wdec@cisco.com" created="Thu, 18 Jun 2015 17:00:57 +0000"  >&lt;p&gt;AFAIK there is no installer for Opendaylight, beyond the tar-ball.&lt;br/&gt;
Clearly the defaults are there to facilitate an admin user who is meant to change the admin credentials. We can have no defaults, but that&apos;s hardly any improvement.&lt;/p&gt;

&lt;p&gt;Bottom line: This appears to be a good feature request for an ODL installer project, and not an AAA bug.&lt;/p&gt;</comment>
                            <comment id="42115" author="rgoulding" created="Tue, 15 Dec 2015 13:18:22 +0000"  >&lt;p&gt;This falls under the realm of an installer project.  There is no sane way to do this as part of the AAA project.&lt;/p&gt;</comment>
                            <comment id="42116" author="dfarrell07" created="Wed, 16 Dec 2015 16:43:14 +0000"  >&lt;p&gt;The closest thing ODL upstream has to an installer atm are the deployment tools provided by Integration/Packaging. I&apos;m not sure we could &quot;prompt&quot; the user at install time, but we might be able to expose the defaults to higher layers where they are more likely to get attention.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://wiki.opendaylight.org/view/Deployment&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://wiki.opendaylight.org/view/Deployment&lt;/a&gt;&lt;br/&gt;
&lt;a href=&quot;https://github.com/dfarrell07/puppet-opendaylight&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/dfarrell07/puppet-opendaylight&lt;/a&gt;&lt;br/&gt;
&lt;a href=&quot;https://github.com/dfarrell07/ansible-opendaylight&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/dfarrell07/ansible-opendaylight&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>668</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=668]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i023hj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>