<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 19:08:30 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[AAA-49] Tokens stored in MDSAL are not encrypted</title>
                <link>https://jira.opendaylight.org/browse/AAA-49</link>
                <project id="10102" key="AAA">aaa</project>
                    <description>&lt;p&gt;If you switch the AAA token store to the MD-SAL store for clustering, tokens are in plain text in the data store, hence you have a security issue.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="22300">AAA-49</key>
            <summary>Tokens stored in MDSAL are not encrypted</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Cannot Reproduce</resolution>
                                        <assignee username="saichler@cisco.com">Sharon Aicler</assignee>
                                    <reporter username="saichler@cisco.com">Sharon Aicler</reporter>
                        <labels>
                    </labels>
                <created>Tue, 14 Jul 2015 05:08:36 +0000</created>
                <updated>Thu, 21 Mar 2019 11:56:42 +0000</updated>
                            <resolved>Thu, 23 Jul 2015 17:28:10 +0000</resolved>
                                                                    <component>General</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="42233" author="rgoulding" created="Tue, 21 Jul 2015 13:33:35 +0000"  >&lt;p&gt;Is this a duplicate of &lt;a href=&quot;https://jira.opendaylight.org/browse/AAA-21&quot; title=&quot;Security Issue in Restconf: Restconf config output produces user name and password in clear text&quot; class=&quot;issue-link&quot; data-issue-key=&quot;AAA-21&quot;&gt;&lt;del&gt;AAA-21&lt;/del&gt;&lt;/a&gt;?  They seem similar but I&apos;m not 100% positive.  Thanks!&lt;/p&gt;</comment>
                            <comment id="42234" author="saichler@cisco.com" created="Tue, 21 Jul 2015 15:32:46 +0000"  >&lt;p&gt;No, The RestConf bug is for passing back and forward user/password in clean text while this bug is for storing token inside the MDSAL data store in a non encrypted way. I guess the same encrypting/decrypting mechanism can be used for different kind of places where encryption is needed, maybe it will be a good idea to place a comment in &lt;a href=&quot;https://jira.opendaylight.org/browse/AAA-21&quot; title=&quot;Security Issue in Restconf: Restconf config output produces user name and password in clear text&quot; class=&quot;issue-link&quot; data-issue-key=&quot;AAA-21&quot;&gt;&lt;del&gt;AAA-21&lt;/del&gt;&lt;/a&gt; stating to be aware of this bug encryption solution.&lt;/p&gt;</comment>
                            <comment id="42235" author="wdec@cisco.com" created="Thu, 23 Jul 2015 15:10:41 +0000"  >&lt;p&gt;Tokens are not in plain text since dcb210ba960fd61c4bd8b8509fe3eb05ac095efd&lt;/p&gt;</comment>
                            <comment id="42236" author="saichler@cisco.com" created="Thu, 23 Jul 2015 17:26:43 +0000"  >&lt;p&gt;Correct, I have not notice that... because my DataEncrypter utility was used, I though I added that...:o) I will junk this bug.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>3992</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=3992]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i023s7:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>