)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"a5f52552c18981f9c49c9bb46e8392fa9796bb95","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"6e65b644_597d488c","updated":"2022-04-22 07:17:28.000000000","message":"There is a docs impact for this change https://opendev.org/openstack/tripleo-docs/src/branch/master/deploy-guide/source/features/security_hardening.rst#L92\n\nAlso I can see some fixtures for the derived params testing do mention that path (I hope that\u0027s fine to delete it though):\nhttps://opendev.org/openstack/tripleo-ansible/src/branch/master/tripleo_ansible/roles/tripleo_derived_parameters/molecule/mock_nfv_params#L4792","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"7fc56b4e72df47b9aa7cc9316993429b24e15aa4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b603b3dd_228413ca","updated":"2022-04-22 07:08:42.000000000","message":"recheck","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"b2d090134c899fba66ec449931442164f691f584","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"cd594365_58a6c663","updated":"2022-05-20 13:56:07.000000000","message":"recheck","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"0ca683aec27c53ffc00722b194726c7a63180e6a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"dd541623_a88976eb","updated":"2022-05-16 23:10:34.000000000","message":"recheck","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"494fa0e46300d7b6ff3139152741540e96c41951","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"ee803b09_38104fc3","in_reply_to":"6e65b644_597d488c","updated":"2022-04-22 07:58:32.000000000","message":"Good catch. I\u0027ve submitted a few patches to address these. Please see the patches with topic:remove-puppet-sshd.","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"}],"deployment/nova/nova-migration-target-container-puppet.yaml":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"8e7b78e385c664fa1153c9b9624e457921a76d46","unresolved":true,"context_lines":[{"line_number":141,"context_line":"          GSSAPICleanupCredentials: \u0027no\u0027"},{"line_number":142,"context_line":"          UsePAM: \u0027yes\u0027"},{"line_number":143,"context_line":"          UseDNS: \u0027no\u0027"},{"line_number":144,"context_line":"          X11Forwarding: \u0027yes\u0027"},{"line_number":145,"context_line":"          AcceptEnv:"},{"line_number":146,"context_line":"            - \u0027LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES\u0027"},{"line_number":147,"context_line":"            - \u0027LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT\u0027"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e17eb61c_3ae10051","line":144,"updated":"2022-04-22 07:14:16.000000000","message":"we might want to disable that in follow ups","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"494fa0e46300d7b6ff3139152741540e96c41951","unresolved":true,"context_lines":[{"line_number":141,"context_line":"          GSSAPICleanupCredentials: \u0027no\u0027"},{"line_number":142,"context_line":"          UsePAM: \u0027yes\u0027"},{"line_number":143,"context_line":"          UseDNS: \u0027no\u0027"},{"line_number":144,"context_line":"          X11Forwarding: \u0027yes\u0027"},{"line_number":145,"context_line":"          AcceptEnv:"},{"line_number":146,"context_line":"            - \u0027LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES\u0027"},{"line_number":147,"context_line":"            - \u0027LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT\u0027"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e6b16cd6_e4e04179","line":144,"in_reply_to":"e17eb61c_3ae10051","updated":"2022-04-22 07:58:32.000000000","message":"Currently we disable X11Forwardning in the match block. However ideally we should disable it in the whole sshd process. The main intention of this patch is to take a full control about the base configruation and we can revisit the other items as well, as a follow-up.","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"b57828a90475cbf422d12f9c3b9b03c316ae0490","unresolved":false,"context_lines":[{"line_number":141,"context_line":"          GSSAPICleanupCredentials: \u0027no\u0027"},{"line_number":142,"context_line":"          UsePAM: \u0027yes\u0027"},{"line_number":143,"context_line":"          UseDNS: \u0027no\u0027"},{"line_number":144,"context_line":"          X11Forwarding: \u0027yes\u0027"},{"line_number":145,"context_line":"          AcceptEnv:"},{"line_number":146,"context_line":"            - \u0027LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES\u0027"},{"line_number":147,"context_line":"            - \u0027LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT\u0027"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"8a6f9fd0_ab5d0f6a","line":144,"in_reply_to":"e6b16cd6_e4e04179","updated":"2022-05-16 23:10:54.000000000","message":"Done","commit_id":"ab2761541e6d453e7596a86d7a40a56255136940"}]}
