From mskrivan at redhat.com Tue Feb 2 04:55:23 2016 Content-Type: multipart/mixed; boundary="===============5470618827932082710==" MIME-Version: 1.0 From: Michal Skrivanek To: devel at ovirt.org Subject: Re: [ovirt-devel] Hello and A Question about oVirt Date: Tue, 02 Feb 2016 10:55:19 +0100 Message-ID: In-Reply-To: CACKMAy_rT+SzpP=JfpmALCiCat5wQWEoxFnfcBX71usJ_cD8aQ@mail.gmail.com --===============5470618827932082710== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable --Apple-Mail=3D_19375BCD-A726-4FD8-9A0F-1BA240197D4D Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=3Dutf-8 > On 02 Feb 2016, at 10:40, Yaniv Dary wrote: >=3D20 > I don't think we have a option like this. Michal? >=3D20 > Yaniv Dary > Technical Product Manager > Red Hat Israel Ltd. > 34 Jerusalem Road > Building A, 4th floor > Ra'anana, Israel 4350109 >=3D20 > Tel : +972 (9) 7692306 > 8272306 > Email: ydary(a)redhat.com > IRC : ydary >=3D20 > On Mon, Feb 1, 2016 at 5:16 AM, zhukaijie > wrote: > Hello, now I have defined a custom property named 'A' in oVirt Engine. = =3D Administrator is responsible for entering the value (and arbitrary =3D string ) of 'A' before starting the VM. After an users trys to start the = =3D VM in oVirt, VDSM will add the value of 'A' in the qemu:arg of libvirt =3D domain xml, so that the value of 'A' will be added into the QEMU Cmd as =3D a param. However, just like the password of VNC or SPICE, I want to hide = =3D the value of 'A' in '*' format in both Libvirt domain xml and QEMU Cmd, =3D So could you please tell me how to achieve it? Thank you very much and =3D happy 2016. No, I don=3DE2=3D80=3D99t think you would be able to make libvirt and qemu = to =3D hide it. Unfortunately it would be exposed=3DE2=3D80=3DA6for log files you = are =3D protected by file access permissions, but if there is anything sensitive = =3D on the command line and you have a user who can get a shell on that =3D machine one can always see that in process listing do you perhaps need to pass some secret to a VM? Might be better via =3D payload, it can be accessed in the guest as a file then. Thanks, michal > _______________________________________________ > Devel mailing list > Devel(a)ovirt.org > http://lists.ovirt.org/mailman/listinfo/devel =3D >=3D20 --Apple-Mail=3D_19375BCD-A726-4FD8-9A0F-1BA240197D4D Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=3Dutf-8
On 02 Feb 2016, at 10:40, Yaniv Dary <ydary(a)redhat.com>= ; =3D wrote:

I don't think we have a option like this. =3D Michal?

=
Yaniv Dary
Technical Product Manager
Red Hat Israel Ltd.
34 Jerusalem Road
Building A, 4th floor
Ra'anana, Israel 4350109

Tel : +972 (9) 7692306
        8272306
Email: ydary(a)redhat.com
IRC : ydary

On Mon, Feb 1, 2016 at 5:16 = =3D AM, zhukaijie <kjzhu14(a)is.ac.cn> wrote:
Hello, now I have =3D defined a custom property named 'A' in oVirt Engine. Administrator is =3D responsible for entering the value (and arbitrary string ) of 'A' before = =3D starting the VM. After an users trys to start the VM in oVirt, VDSM will = =3D add the value of 'A' in the qemu:arg of libvirt domain xml, so that the =3D value of 'A' will be added into the QEMU Cmd as a param. However, just =3D like the password of VNC or SPICE, I want to hide the value of 'A' in =3D '*' format in both Libvirt domain xml and QEMU Cmd, So could you please =3D tell me how to achieve it? Thank you very much and happy 2016.

No, I don=3DE2=3D80=3D99t think you would be able to mak= e =3D libvirt and qemu to hide it. Unfortunately it would be exposed=3DE2=3D80=3D= A6for=3D log files you are protected by file access permissions, but if there is = =3D anything sensitive on the command line and you have a user who can get a = =3D shell on that machine one can always see that in process =3D listing

do you perhaps need to pass = =3D some secret to a VM? Might be better via payload, it can be accessed in =3D the guest as a file then.

Thanks,
michal

_______________________________________________
Devel mailing list
Devel(a)ovirt.org http://lists.ovirt.org/mailman/listinfo/devel


=3D --Apple-Mail=3D_19375BCD-A726-4FD8-9A0F-1BA240197D4D-- --===============5470618827932082710== Content-Type: multipart/alternative MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.bin" Ci0tQXBwbGUtTWFpbD1fMTkzNzVCQ0QtQTcyNi00RkQ4LTlBMEYtMUJBMjQwMTk3RDRECkNvbnRl bnQtVHJhbnNmZXItRW5jb2Rpbmc6IHF1b3RlZC1wcmludGFibGUKQ29udGVudC1UeXBlOiB0ZXh0 L3BsYWluOwoJY2hhcnNldD11dGYtOAoKCj4gT24gMDIgRmViIDIwMTYsIGF0IDEwOjQwLCBZYW5p diBEYXJ5IDx5ZGFyeUByZWRoYXQuY29tPiB3cm90ZToKPj0yMAo+IEkgZG9uJ3QgdGhpbmsgd2Ug aGF2ZSBhIG9wdGlvbiBsaWtlIHRoaXMuIE1pY2hhbD8KPj0yMAo+IFlhbml2IERhcnkKPiBUZWNo bmljYWwgUHJvZHVjdCBNYW5hZ2VyCj4gUmVkIEhhdCBJc3JhZWwgTHRkLgo+IDM0IEplcnVzYWxl bSBSb2FkCj4gQnVpbGRpbmcgQSwgNHRoIGZsb29yCj4gUmEnYW5hbmEsIElzcmFlbCA0MzUwMTA5 Cj49MjAKPiBUZWwgOiArOTcyICg5KSA3NjkyMzA2Cj4gICAgICAgICA4MjcyMzA2Cj4gRW1haWw6 IHlkYXJ5QHJlZGhhdC5jb20gPG1haWx0bzp5ZGFyeUByZWRoYXQuY29tPgo+IElSQyA6IHlkYXJ5 Cj49MjAKPiBPbiBNb24sIEZlYiAxLCAyMDE2IGF0IDU6MTYgQU0sIHpodWthaWppZSA8a2p6aHUx NEBpcy5hYy5jbiA9CjxtYWlsdG86a2p6aHUxNEBpcy5hYy5jbj4+IHdyb3RlOgo+IEhlbGxvLCBu b3cgSSBoYXZlIGRlZmluZWQgYSBjdXN0b20gcHJvcGVydHkgbmFtZWQgJ0EnIGluIG9WaXJ0IEVu Z2luZS4gPQpBZG1pbmlzdHJhdG9yIGlzIHJlc3BvbnNpYmxlIGZvciBlbnRlcmluZyB0aGUgdmFs dWUgKGFuZCBhcmJpdHJhcnkgPQpzdHJpbmcgKSBvZiAnQScgYmVmb3JlIHN0YXJ0aW5nIHRoZSBW TS4gQWZ0ZXIgYW4gdXNlcnMgdHJ5cyB0byBzdGFydCB0aGUgPQpWTSBpbiBvVmlydCwgVkRTTSB3 aWxsIGFkZCB0aGUgdmFsdWUgb2YgJ0EnIGluIHRoZSBxZW11OmFyZyBvZiBsaWJ2aXJ0ID0KZG9t YWluIHhtbCwgc28gdGhhdCB0aGUgdmFsdWUgb2YgJ0EnIHdpbGwgYmUgYWRkZWQgaW50byB0aGUg UUVNVSBDbWQgYXMgPQphIHBhcmFtLiBIb3dldmVyLCBqdXN0IGxpa2UgdGhlIHBhc3N3b3JkIG9m IFZOQyBvciBTUElDRSwgSSB3YW50IHRvIGhpZGUgPQp0aGUgdmFsdWUgb2YgJ0EnIGluICcqJyBm b3JtYXQgaW4gYm90aCBMaWJ2aXJ0IGRvbWFpbiB4bWwgYW5kIFFFTVUgQ21kLCA9ClNvIGNvdWxk IHlvdSBwbGVhc2UgdGVsbCBtZSBob3cgdG8gYWNoaWV2ZSBpdD8gVGhhbmsgeW91IHZlcnkgbXVj aCBhbmQgPQpoYXBweSAyMDE2LgoKTm8sIEkgZG9uPUUyPTgwPTk5dCB0aGluayB5b3Ugd291bGQg YmUgYWJsZSB0byBtYWtlIGxpYnZpcnQgYW5kIHFlbXUgdG8gPQpoaWRlIGl0LiBVbmZvcnR1bmF0 ZWx5IGl0IHdvdWxkIGJlIGV4cG9zZWQ9RTI9ODA9QTZmb3IgbG9nIGZpbGVzIHlvdSBhcmUgPQpw cm90ZWN0ZWQgYnkgZmlsZSBhY2Nlc3MgcGVybWlzc2lvbnMsIGJ1dCBpZiB0aGVyZSBpcyBhbnl0 aGluZyBzZW5zaXRpdmUgPQpvbiB0aGUgY29tbWFuZCBsaW5lIGFuZCB5b3UgaGF2ZSBhIHVzZXIg d2hvIGNhbiBnZXQgYSBzaGVsbCBvbiB0aGF0ID0KbWFjaGluZSBvbmUgY2FuIGFsd2F5cyBzZWUg dGhhdCBpbiBwcm9jZXNzIGxpc3RpbmcKCmRvIHlvdSBwZXJoYXBzIG5lZWQgdG8gcGFzcyBzb21l IHNlY3JldCB0byBhIFZNPyBNaWdodCBiZSBiZXR0ZXIgdmlhID0KcGF5bG9hZCwgaXQgY2FuIGJl IGFjY2Vzc2VkIGluIHRoZSBndWVzdCBhcyBhIGZpbGUgdGhlbi4KClRoYW5rcywKbWljaGFsCgo+ IF9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCj4gRGV2ZWwg bWFpbGluZyBsaXN0Cj4gRGV2ZWxAb3ZpcnQub3JnIDxtYWlsdG86RGV2ZWxAb3ZpcnQub3JnPgo+ IGh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0aW5mby9kZXZlbCA9CjxodHRwOi8v bGlzdHMub3ZpcnQub3JnL21haWxtYW4vbGlzdGluZm8vZGV2ZWw+Cj49MjAKCgotLUFwcGxlLU1h aWw9XzE5Mzc1QkNELUE3MjYtNEZEOC05QTBGLTFCQTI0MDE5N0Q0RApDb250ZW50LVRyYW5zZmVy LUVuY29kaW5nOiBxdW90ZWQtcHJpbnRhYmxlCkNvbnRlbnQtVHlwZTogdGV4dC9odG1sOwoJY2hh cnNldD11dGYtOAoKPGh0bWw+PGhlYWQ+PG1ldGEgaHR0cC1lcXVpdj0zRCJDb250ZW50LVR5cGUi IGNvbnRlbnQ9M0QidGV4dC9odG1sID0KY2hhcnNldD0zRHV0Zi04Ij48L2hlYWQ+PGJvZHkgc3R5 bGU9M0Qid29yZC13cmFwOiBicmVhay13b3JkOyA9Ci13ZWJraXQtbmJzcC1tb2RlOiBzcGFjZTsg LXdlYmtpdC1saW5lLWJyZWFrOiBhZnRlci13aGl0ZS1zcGFjZTsiID0KY2xhc3M9M0QiIj48YnIg Y2xhc3M9M0QiIj48ZGl2PjxibG9ja3F1b3RlIHR5cGU9M0QiY2l0ZSIgY2xhc3M9M0QiIj48ZGl2 ID0KY2xhc3M9M0QiIj5PbiAwMiBGZWIgMjAxNiwgYXQgMTA6NDAsIFlhbml2IERhcnkgJmx0Ozxh ID0KaHJlZj0zRCJtYWlsdG86eWRhcnlAcmVkaGF0LmNvbSIgY2xhc3M9M0QiIj55ZGFyeUByZWRo YXQuY29tPC9hPiZndDsgPQp3cm90ZTo8L2Rpdj48YnIgY2xhc3M9M0QiQXBwbGUtaW50ZXJjaGFu Z2UtbmV3bGluZSI+PGRpdiBjbGFzcz0zRCIiPjxkaXYgPQpkaXI9M0QibHRyIiBjbGFzcz0zRCIi PkkgZG9uJ3QgdGhpbmsgd2UgaGF2ZSBhIG9wdGlvbiBsaWtlIHRoaXMuID0KTWljaGFsPzwvZGl2 PjxkaXYgY2xhc3M9M0QiZ21haWxfZXh0cmEiPjxiciBjbGVhcj0zRCJhbGwiIGNsYXNzPTNEIiI+ PGRpdiA9CmNsYXNzPTNEIiI+PGRpdiBjbGFzcz0zRCJnbWFpbF9zaWduYXR1cmUiPjxkaXYgZGly PTNEImx0ciIgY2xhc3M9M0QiIj48ZGl2PQogY2xhc3M9M0QiIj48ZGl2IGRpcj0zRCJsdHIiIGNs YXNzPTNEIiI+PHByZSBjb2xzPTNEIjcyIiBjbGFzcz0zRCIiPjxzcGFuID0Kc3R5bGU9M0QiZm9u dC1mYW1pbHk6YXJpYWwsaGVsdmV0aWNhLHNhbnMtc2VyaWYiIGNsYXNzPTNEIiI+WWFuaXYgRGFy eQpUZWNobmljYWwgUHJvZHVjdCBNYW5hZ2VyClJlZCBIYXQgSXNyYWVsIEx0ZC4KMzQgSmVydXNh bGVtIFJvYWQKQnVpbGRpbmcgQSwgNHRoIGZsb29yClJhJ2FuYW5hLCBJc3JhZWwgNDM1MDEwOQoK VGVsIDogKzk3MiAoOSkgNzY5MjMwNgogICAgICAgIDgyNzIzMDYKRW1haWw6IDxhIGhyZWY9M0Qi bWFpbHRvOnlkYXJ5QHJlZGhhdC5jb20iIHRhcmdldD0zRCJfYmxhbmsiID0KY2xhc3M9M0QiIj55 ZGFyeUByZWRoYXQuY29tPC9hPgpJUkMgOiB5ZGFyeTwvc3Bhbj48L3ByZT4KPC9kaXY+PC9kaXY+ PC9kaXY+PC9kaXY+PC9kaXY+CjxiciBjbGFzcz0zRCIiPjxkaXYgY2xhc3M9M0QiZ21haWxfcXVv dGUiPk9uIE1vbiwgRmViIDEsIDIwMTYgYXQgNToxNiA9CkFNLCB6aHVrYWlqaWUgPHNwYW4gZGly PTNEImx0ciIgY2xhc3M9M0QiIj4mbHQ7PGEgPQpocmVmPTNEIm1haWx0bzpranpodTE0QGlzLmFj LmNuIiB0YXJnZXQ9M0QiX2JsYW5rIiA9CmNsYXNzPTNEIiI+a2p6aHUxNEBpcy5hYy5jbjwvYT4m Z3Q7PC9zcGFuPiB3cm90ZTo8YnIgPQpjbGFzcz0zRCIiPjxibG9ja3F1b3RlIGNsYXNzPTNEImdt YWlsX3F1b3RlIiBzdHlsZT0zRCJtYXJnaW46MCAwIDAgPQouOGV4O2JvcmRlci1sZWZ0OjFweCAj Y2NjIHNvbGlkO3BhZGRpbmctbGVmdDoxZXgiPkhlbGxvLCBub3cgSSBoYXZlID0KZGVmaW5lZCBh IGN1c3RvbSBwcm9wZXJ0eSBuYW1lZCAnQScgaW4gb1ZpcnQgRW5naW5lLiBBZG1pbmlzdHJhdG9y IGlzID0KcmVzcG9uc2libGUgZm9yIGVudGVyaW5nIHRoZSB2YWx1ZSAoYW5kIGFyYml0cmFyeSBz dHJpbmcgKSBvZiAnQScgYmVmb3JlID0Kc3RhcnRpbmcgdGhlIFZNLiBBZnRlciBhbiB1c2VycyB0 cnlzIHRvIHN0YXJ0IHRoZSBWTSBpbiBvVmlydCwgVkRTTSB3aWxsID0KYWRkIHRoZSB2YWx1ZSBv ZiAnQScgaW4gdGhlIHFlbXU6YXJnIG9mIGxpYnZpcnQgZG9tYWluIHhtbCwgc28gdGhhdCB0aGUg PQp2YWx1ZSBvZiAnQScgd2lsbCBiZSBhZGRlZCBpbnRvIHRoZSBRRU1VIENtZCBhcyBhIHBhcmFt LiBIb3dldmVyLCBqdXN0ID0KbGlrZSB0aGUgcGFzc3dvcmQgb2YgVk5DIG9yIFNQSUNFLCBJIHdh bnQgdG8gaGlkZSB0aGUgdmFsdWUgb2YgJ0EnIGluID0KJyonIGZvcm1hdCBpbiBib3RoIExpYnZp cnQgZG9tYWluIHhtbCBhbmQgUUVNVSBDbWQsIFNvIGNvdWxkIHlvdSBwbGVhc2UgPQp0ZWxsIG1l IGhvdyB0byBhY2hpZXZlIGl0PyBUaGFuayB5b3UgdmVyeSBtdWNoIGFuZCBoYXBweSAyMDE2Ljxi ciA9CmNsYXNzPTNEIiI+PC9ibG9ja3F1b3RlPjwvZGl2PjwvZGl2PjwvZGl2PjwvYmxvY2txdW90 ZT48ZGl2PjxiciA9CmNsYXNzPTNEIiI+PC9kaXY+Tm8sIEkgZG9uPUUyPTgwPTk5dCB0aGluayB5 b3Ugd291bGQgYmUgYWJsZSB0byBtYWtlID0KbGlidmlydCBhbmQgcWVtdSB0byBoaWRlIGl0LiBV bmZvcnR1bmF0ZWx5IGl0IHdvdWxkIGJlIGV4cG9zZWQ9RTI9ODA9QTZmb3I9CiBsb2cgZmlsZXMg eW91IGFyZSBwcm90ZWN0ZWQgYnkgZmlsZSBhY2Nlc3MgcGVybWlzc2lvbnMsIGJ1dCBpZiB0aGVy ZSBpcyA9CmFueXRoaW5nIHNlbnNpdGl2ZSBvbiB0aGUgY29tbWFuZCBsaW5lIGFuZCB5b3UgaGF2 ZSBhIHVzZXIgd2hvIGNhbiBnZXQgYSA9CnNoZWxsIG9uIHRoYXQgbWFjaGluZSBvbmUgY2FuIGFs d2F5cyBzZWUgdGhhdCBpbiBwcm9jZXNzID0KbGlzdGluZzwvZGl2PjxkaXY+PGJyIGNsYXNzPTNE IiI+PC9kaXY+PGRpdj5kbyB5b3UgcGVyaGFwcyBuZWVkIHRvIHBhc3MgPQpzb21lIHNlY3JldCB0 byBhIFZNPyBNaWdodCBiZSBiZXR0ZXIgdmlhIHBheWxvYWQsIGl0IGNhbiBiZSBhY2Nlc3NlZCBp biA9CnRoZSBndWVzdCBhcyBhIGZpbGUgdGhlbi48L2Rpdj48ZGl2PjxiciA9CmNsYXNzPTNEIiI+ PC9kaXY+PGRpdj5UaGFua3MsPC9kaXY+PGRpdj5taWNoYWw8L2Rpdj48ZGl2PjxiciA9CmNsYXNz PTNEIiI+PGJsb2NrcXVvdGUgdHlwZT0zRCJjaXRlIiBjbGFzcz0zRCIiPjxkaXYgY2xhc3M9M0Qi Ij48ZGl2ID0KY2xhc3M9M0QiZ21haWxfZXh0cmEiPjxkaXYgY2xhc3M9M0QiZ21haWxfcXVvdGUi PjxibG9ja3F1b3RlID0KY2xhc3M9M0QiZ21haWxfcXVvdGUiIHN0eWxlPTNEIm1hcmdpbjowIDAg MCAuOGV4O2JvcmRlci1sZWZ0OjFweCAjY2NjID0Kc29saWQ7cGFkZGluZy1sZWZ0OjFleCI+Cl9f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyIGNsYXNzPTNE IiI+CkRldmVsIG1haWxpbmcgbGlzdDxiciBjbGFzcz0zRCIiPgo8YSBocmVmPTNEIm1haWx0bzpE ZXZlbEBvdmlydC5vcmciIGNsYXNzPTNEIiI+RGV2ZWxAb3ZpcnQub3JnPC9hPjxiciA9CmNsYXNz PTNEIiI+CjxhIGhyZWY9M0QiaHR0cDovL2xpc3RzLm92aXJ0Lm9yZy9tYWlsbWFuL2xpc3RpbmZv L2RldmVsIiA9CnJlbD0zRCJub3JlZmVycmVyIiB0YXJnZXQ9M0QiX2JsYW5rIiA9CmNsYXNzPTNE IiI+aHR0cDovL2xpc3RzLm92aXJ0Lm9yZy9tYWlsbWFuL2xpc3RpbmZvL2RldmVsPC9hPjxiciA9 CmNsYXNzPTNEIiI+CjwvYmxvY2txdW90ZT48L2Rpdj48YnIgY2xhc3M9M0QiIj48L2Rpdj4KPC9k aXY+PC9ibG9ja3F1b3RlPjwvZGl2PjxiciBjbGFzcz0zRCIiPjwvYm9keT48L2h0bWw+PQoKLS1B cHBsZS1NYWlsPV8xOTM3NUJDRC1BNzI2LTRGRDgtOUEwRi0xQkEyNDAxOTdENEQtLQo= --===============5470618827932082710==--