)]}'
{"id":"openstack%2Fnova-specs~788116","triplet_id":"openstack%2Fnova-specs~master~I1369b959d1e480862c0b08680704561990f29620","project":"openstack/nova-specs","branch":"master","topic":"bp/nova-support-webvnc-with-password-anthentication","hashtags":[],"change_id":"I1369b959d1e480862c0b08680704561990f29620","subject":"Proposal for a safer remote console with password authentication","status":"ABANDONED","created":"2021-04-27 01:53:37.000000000","updated":"2021-07-19 12:33:09.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"534b41252efd87ba4ec8b3dffeac5233125c586f","_number":788116,"virtual_id_number":788116,"owner":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"tag":"autogenerated:zuul:check","value":1,"date":"2021-04-27 02:06:54.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"rejected":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"all":[{"value":-1,"date":"2021-05-25 23:14:49.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":-1,"date":"2021-04-27 08:15:35.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":-1,"date":"2021-05-17 13:39:09.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":-2,"date":"2021-07-16 13:01:40.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"rejected":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":-1,"date":"2021-07-19 01:03:57.000000000","permitted_voting_range":{"min":-1,"max":0},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{" 0":"Default Priority","+1":"Contributor Review Promise","+2":"Core Review Promise"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-04-27 01:56:52.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},"state":"REVIEWER"},{"updated":"2021-04-27 01:56:52.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"state":"REVIEWER"},{"updated":"2021-04-27 01:56:52.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"},{"updated":"2021-04-27 01:56:52.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"state":"REVIEWER"},{"updated":"2021-04-27 02:06:54.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-05-25 23:14:49.000000000","updated_by":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"reviewer":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"state":"REVIEWER"}],"messages":[{"id":"0282ebbac2b171f3d02ab7f2a30712c4cedc144e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2021-04-27 01:53:37.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e8bb80d266f76aaec0b3a38994a5db536174efa0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-27 02:06:54.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1e8b3dac64fd4fb0a3e34d9591f428b0 : SUCCESS in 12m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b3d90691c39946c4986e8d6daa9eb117 : SUCCESS in 4m 10s","accounts_in_message":[],"_revision_number":1},{"id":"602b590f5764415c6b07c60f9823e6409edc7563","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2021-04-27 08:15:35.000000000","message":"Patch Set 1: Code-Review-1\n\nupdating this with the deiscussion form the ptg below.\ni think we need to do more then a simple reporposal here and consider if this is the correct solution to the problem.\n\n(brinzhang) Nova supports password encrypted VNC https://review.opendev.org/c/openstack/nova/+/622336\n\n    This aims at providing a safer remote console with password authentication to promote the security of opening server\u0027s console, but there are some issue when we implement it\n\n    In summary, if we want to support reseting password for vnc\n\n    (a)with get_vnc_console API, it must be hard reboot,\n\n    (b)with server create API, it\u0027s too intrusive to the VM system;,\n\n    (c)with config-driven API behavior, looks better than before options, but it\u0027s also not have a good UX for users, the same as give the warning with exceptions.\n\n    (gibi): Do I understand correctly from the discussion in review that \"vencrypt\" auth type we support today is overal better than the proposed password auth? What do we loose if we only support \"vencrypt\"? \n\n    see melwitt\u0027s comment in https://review.opendev.org/c/openstack/nova/+/622336/37#message-0decdf04e81e999a1458b5b6129ef667f4ffe15a\n\n    (melwitt): Given the lack of clean solution option for providing the password auth option, I would like to understand more what is the use case driving this feature request and how/why does the vencrypt auth scheme not fulfill it? My thinking is we would need a strong reason to add such a feature with poor user experience characteristics, IMHO.\n\n    a seperate issue is should we be using barbican for password storage.\n\n    AGREED:\n\n    might be a solution to move the session key from the query string to the header and then the existing ssl support hides the key\n\n    Query string is already encrypted in SSL (host isn\u0027t for SNI, but query string is), no need to change anything.\n\n    If the spec is reproposed then we will request new investigations about alternative solutions. (Stephen has ideas)","accounts_in_message":[],"_revision_number":1},{"id":"ec44a73f8229a8ad80ca2376611e6434e4627b18","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2021-05-17 11:45:58.000000000","message":"Patch Set 1:\n\nFrom TPG aggrement, this spec need stepenfin\u0027s review, and give some advice, right?","accounts_in_message":[],"_revision_number":1},{"id":"82ba143385766fad417cdca0aa2a354de1b65929","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2021-05-17 13:39:09.000000000","message":"Patch Set 1: Code-Review-1\n\nYes, so this isn\u0027t ready to go in its current state since it still has the same issues that prevented it from merging last cycle. I think it would be good to investigate whether we can provide a password at the websocketproxy layer rather than via libvirt. This would allow us to workaround libvirt\u0027s limitations. We could also look into vencrypt+password authentication. Ultimately someone needs to build up a strong understanding of how the current VNC setup works since I think we have lost a lot of this knowledge over the past few years.","accounts_in_message":[],"_revision_number":1},{"id":"7f8ec95b086c81f07618f37c2c7c737ccd4f35b6","author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"date":"2021-05-25 23:14:49.000000000","message":"Patch Set 1: Code-Review-1\n\nAgreed with stephenfin, with what we discovered during the previous review and testing, I don\u0027t see any way for the libvirt vnc password approach to result in a good user experience.\n\nThe reason I mentioned the use case for having a password is because the token already serves as a type of password for accessing the console. You have to know the token to be granted access to the console and the default TTL for the token is 10 minutes, so it is rotated often. I am struggling to understand why the token itself is not considered to be enough of a \"password\" and what is the use case for having essentially a second password?","accounts_in_message":[],"_revision_number":1},{"id":"523733c6d319783fa7220e5bd4c0fb51f68529e4","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2021-05-26 12:29:43.000000000","message":"Patch Set 1:\n\n\u003e Patch Set 1: Code-Review-1\n\u003e \n\u003e Agreed with stephenfin, with what we discovered during the previous review and testing, I don\u0027t see any way for the libvirt vnc password approach to result in a good user experience.\n\u003e \n\u003e The reason I mentioned the use case for having a password is because the token already serves as a type of password for accessing the console. You have to know the token to be granted access to the console and the default TTL for the token is 10 minutes, so it is rotated often. I am struggling to understand why the token itself is not considered to be enough of a \"password\" and what is the use case for having essentially a second password?\n\ni would speculate that the reason for this is the token can be retrived by anyone in the same project\nwhere as a per instace passward woudl be known only to the user that set it.\nthe problem with that argument is anyone in the porject can just update the password.\n\nthe token is a bearer token and as you said is intended to act as a password.\nif ssl is used to secure the api endpoint including the novnc proxy then there\nshoudl not be a man in the middle attack vector so without the password mechanium\nbeing robust i dont think it adds suffenct value.","accounts_in_message":[],"_revision_number":1},{"id":"d2df696a3c02d08117f6d7e7b3c02dc74d857411","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2021-07-16 13:01:40.000000000","message":"Patch Set 1: Code-Review-2\n\nProcedural -2: We hit spec freeze. If you are still working on this the please re-propose it to Yoga.","accounts_in_message":[],"_revision_number":1},{"id":"077a3113e71c6eb2354d7509085f44e60606c66c","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2021-07-19 01:03:57.000000000","message":"Patch Set 1: Workflow-1\n\n\u003e Patch Set 1: Code-Review-2\n\u003e \n\u003e Procedural -2: We hit spec freeze. If you are still working on this the please re-propose it to Yoga.\n\nAll I saw was a risk analysis, and I didn\u0027t seem to see effective recommendations.\nSecurity and ease of use we need to make a choice, I will no longer insist on this change, thank you.","accounts_in_message":[],"_revision_number":1},{"id":"534b41252efd87ba4ec8b3dffeac5233125c586f","tag":"autogenerated:gerrit:abandon","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2021-07-19 12:33:09.000000000","message":"Abandoned\n\nBrin: All I saw was a risk analysis, and I didn\u0027t seem to see effective recommendations.\nSecurity and ease of use we need to make a choice, I will no longer insist on this change, thank you.","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"aed42f0b500b1581331ec4260da39cb7f8fa2252","revisions":{"aed42f0b500b1581331ec4260da39cb7f8fa2252":{"kind":"REWORK","_number":1,"created":"2021-04-27 01:53:37.000000000","uploader":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"ref":"refs/changes/16/788116/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/16/788116/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/16/788116/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/16/788116/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/16/788116/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/16/788116/1"}}},"commit":{"parents":[{"commit":"8411c164db8884dbb778d4defdb92369867550c0","subject":"Merge \"trivial: Fix spelling, formatting of vDPA spec\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/8411c164db8884dbb778d4defdb92369867550c0"}]}],"author":{"name":"zhangbailin","email":"zhangbailin@inspur.com","date":"2021-04-26 06:29:21.000000000","tz":480},"committer":{"name":"zhangbailin","email":"zhangbailin@inspur.com","date":"2021-04-26 06:29:24.000000000","tz":480},"subject":"Proposal for a safer remote console with password authentication","message":"Proposal for a safer remote console with password authentication\n\nThe feature aims at providing a safer remote console with password\nauthentication. End users can set console password for their instances.\nAny user trying to access the password-encrypted console of instance\nwill get a locked window from web console prompting for ``password``\ninput, and this provides almost the same experience as using VNC clients\n(e.g vncviewer) to access vnc servers that require password\nauthentication.\n\nPreviously-Approved: Wallaby\nPartially-Implements: blueprint nova-support-webvnc-with-password-anthentication\n\nChange-Id: I1369b959d1e480862c0b08680704561990f29620\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/aed42f0b500b1581331ec4260da39cb7f8fa2252"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/aed42f0b500b1581331ec4260da39cb7f8fa2252"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
