Repository navigation
Conversation
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What is this change about?
Harden HTTPS agent passwords against the metadata exposure reported in the discovered CVE. The agent accepts a salted HMAC-SHA256 verifier in its mbus URL and checks the original HTTP Basic Auth password with constant-time comparison. The verifier itself cannot be replayed as a password. Existing clients keep sending their original credentials.
The password must be cryptographically random. This fast verifier deliberately does not stretch weak passwords; the companion CLI warns about offline guessing. Authentication uses no concurrency limiter, wait timeout, or HTTP 503 response. Legacy plaintext authentication remains supported, and malformed verifiers prevent listener startup.
Please provide contextual information.
Companion CLI: cloudfoundry/bosh-cli#742.
Companion stemcell builder: cloudfoundry/bosh-linux-stemcell-builder#761.
The
-featuresflag reports capabilities as JSON without starting agent services. The builder advertiseshttp-password-hmac-sha256from the packaged binary. This separate agent capability leaves the CPIapi_versioncontract unchanged. Format and rollout details are indocs/http-agent-password-verifiers.md.What tests have you run against this PR?
The earlier PBKDF2 revision passed
go test -race ./mbusandgo test ./app ./main ./mbus. Those results do not validate the HMAC revision. Current packages compile withgo build ./mbus ./app ./main; the existing verifier fixtures and assertions have been updated but have not been rerun. The HMAC fixture was generated independently with Python's standard library.How should this change be described in bosh-agent release notes?
Support salted HTTPS agent password verifiers to harden newly written VM metadata against reusable password exposure.
Does this PR introduce a breaking change?
Legacy authentication remains supported. The
bosh-hmac-sha256$prefix is reserved; verifier-backed passwords support 1 to 1,024 bytes. Deployments must use cryptographically random passwords.Security scope and rollout
This is hardening, not complete remediation of historical credential exposure. Rotate exposed credentials first to invalidate historical copies. Existing VMs are not rewritten by a no-change create-env run.
Agent TLS private keys and other secrets remain in metadata. An exposed TLS private key can allow agent impersonation and compromise client passwords. Assess and rotate those credentials as appropriate; password verifiers alone do not close that exposure.