Repository navigation
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Harden newly written HTTPS agent metadata against reusable password exposure reported in the discovered CVE. For supporting stemcells, create-env writes a salted HMAC-SHA256 verifier instead of the agent password.
The CLI detects
agent_features: [http-password-hmac-sha256]instemcell.MF. It transformscloud_provider.properties.agent.mbusand overriding resource-poolenv.bosh.mbus.urlsbefore rendering CPI configuration. Client credentials, interpolation variables, and credential stores retain the original password. HTTP clients and health checks need no capability detection. NATS URLs are preserved.The fast verifier requires cryptographically random passwords. The CLI warns that hardcoded or predictable passwords remain vulnerable to offline guessing; password length alone cannot establish entropy. The companion agent uses constant-time comparison without a verification queue, wait timeout, or HTTP 503 response.
Companion agent: cloudfoundry/bosh-agent#487.
Companion stemcell builder: cloudfoundry/bosh-linux-stemcell-builder#761. The builder queries the packaged agent's
-featuresoutput. Capability advertisement follows the binary without changing CPIapi_version. A normal supporting-agent release bump activates it; stemcells without the marker retain legacy behavior. The capability survives repacking.Breaking change requiring rollout review
Supporting stemcells require an explicit
cloud_provider.properties.agent.mbus. A stemcell upgrade can therefore reject a manifest that previously relied on implicit CPI credential defaults. Configure this field before upgrading; whether to retain this requirement remains a draft review decision.Validation
The earlier PBKDF2 revision passed
go test ./agentpassword ./stemcell ./cmd. Those results do not validate the HMAC revision. Current packages compile withgo build ./agentpassword ./stemcell ./cmd. Existing verifier and capability assertions have been updated but have not been rerun.Security scope and rollout
This is hardening, not complete remediation of historical credential exposure. Rotate exposed credentials first to invalidate historical copies. Existing VMs are not rewritten by a no-change create-env run. Recreating with the same password does not invalidate historical copies.
Agent TLS private keys and other secrets remain in metadata. An exposed TLS private key can allow agent impersonation and compromise client passwords. Assess and rotate those credentials as appropriate. See
docs/http-agent-password-verifiers.mdfor the contract and limits.