Repository navigation
[Hardening] F-13: Weak Default Password and Database Encryption Key. #13341
Description
Activity
for the management key and database encryption key, user can specify them when run setup-cloudstack-database
users are also able migrate cloudstack database with new management key or database key by migrate-cloudstack-database.despite it, I think the suggestion makes sense.
for the management key and database encryption key, user can specify them when run setup-cloudstack-database users are also able migrate cloudstack database with new management key or database key by migrate-cloudstack-database.
despite it, I think the suggestion makes sense.
Hey Wei, I did not know that. I will read more about this command
migrate-cloudstack-databas. Thank you!for the management key and database encryption key, user can specify them when run setup-cloudstack-database users are also able migrate cloudstack database with new management key or database key by migrate-cloudstack-database.
despite it, I think the suggestion makes sense.Hey Wei, I did not know that. I will read more about this command
migrate-cloudstack-databas. Thank you!@davift
sorry, the correct command iscloudstack-migrate-database
You may refer to
https://cwiki.apache.org/confluence/display/CLOUDSTACK/New+database+encryption+cipher+-+AeadBase64Encryptor
https://www.shapeblue.com/new-cloudstack-database-encryption-engine/Reacted by Davi TorresI will just drop the example steps here for those who say TLDR.
systemctl stop cloudstack-management systemctl stop cloudstack-usage mysqldump --no-tablespaces --lock-tables=false -R cloud > cloud.sql mysqldump --no-tablespaces --lock-tables=false -R cloud_usage > cloud_usage.sql cloudstack-migrate-databases -d "password" -m "password" -e "<new_db_key>" -n "<new_mgmt_key>" systemctl start cloudstack-management systemctl start cloudstack-usage
I will just drop the example steps here for those who say TLDR.
systemctl stop cloudstack-management
systemctl stop cloudstack-usage
mysqldump --no-tablespaces --lock-tables=false -R cloud > cloud.sql
mysqldump --no-tablespaces --lock-tables=false -R cloud_usage > cloud_usage.sql
cloudstack-migrate-databases -d "password" -m "password" -e "<new_db_key>" -n "<new_mgmt_key>"
systemctl start cloudstack-management
systemctl start cloudstack-usage@davift
Before migrating the database, it is recommended to back up the /etc/cloudstack/management directory as well, including the key and db.properties files.Reacted by Davi Torres🎯 Triage report
Requests that CloudStack randomize the default admin password and database encryption key at install time instead of shipping both as the well-known string "password". A maintainer confirmed the key/password can already be customized via
setup-cloudstack-database/cloudstack-migrate-databases, but agreed the suggestion (safer defaults, no usable default) has merit.📊 Assessment
Dimension Value Reasoning Type type:enhancement Hardening/installation-flow improvement request, not a functional defect. Component component:management-server Affects installation/setup and encryption-key handling in the management server. Severity n/a Hardening enhancement, not a bug with a severity. Labels type:enhancement, component:management-server See above Coding agent Needs more info Underlying tooling already exists ( cloudstack-migrate-databases); the actual change (prompting for/generating a random key and admin password at install/setup time) needs a maintainer decision on backward compatibility and packaging/installer flow before implementation.💡 Notes and suggestions
Related docs already exist on rotating the DB encryption key: (cwiki.apache.org/redacted) . Consider whether this issue should be scoped down to "installer prompts for/generates secure defaults" rather than changing runtime defaults.
Generated by Daily Issue Triage · sonnet50 262K · ◷
Add this agentic workflows to your repo
To install this agentic workflow, run
gh aw add githubnext/agentics/workflows/daily-issue-triage.md@d7c1dc4b72b00607a67caaffdcc216cb64379cf9
Metadata
Metadata
Assignees
Type
Projects
- StatusShow more project fieldsTodo
The required feature described as a wish
Description: CloudStack ships with a default administrative password and database encryption key, both set to the string "password". Neither value is randomized at install time, and the administrator is not prompted to change them during setup. Note that the database encryption key cannot be changed afterwards.
Affected Components: Management
Impact: An attacker with knowledge of the default credentials, which are publicly documented, can authenticate to the CloudStack Management UI without any prior reconnaissance or effort. Additionally, if the database encryption key is not changed, an attacker who gains read access to the database (e.g., via SQL injection, a misconfigured backup, or direct server access) can decrypt all protected fields, including API secret keys, passwords, and other credentials, using the known default key.
Steps to Reproduce:
adminand the passwordpassword.password.Recommended Remediation: Generate a unique password and database encryption key from a reliable source of entropy during installation (before the system becomes operational). Neither value should have a usable default.