Thursday, 2021-08-05

opendevreviewLance Bragstad proposed openstack/keystone master: Add test to expose app cred secret hash truncating CVE  https://review.opendev.org/c/openstack/keystone/+/80364118:30
lbragstadgagehugo curious what you think the right fix is for that ^ 18:37
gagehugoI can take a look once i get home18:46
lbragstadsounds good- thnaks18:52
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org is going down for a quick restart to adjust its database connection configuration, and should return to service momentarily20:03
gagehugoI guess force a char length for app cred secrets?20:08
gagehugoenforce*20:08
lbragstadgagehugo that would be one way to do it20:21
lbragstadgagehugo the hash colume for application credentials is the same length as the hash colume for passwords20:21

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!