Skip to content
This repository has been archived by the owner on Feb 21, 2018. It is now read-only.

changes to duo.conf expose the ikey/skey values in the syslog #20

Open
ghost opened this issue Nov 11, 2015 · 1 comment
Open

changes to duo.conf expose the ikey/skey values in the syslog #20

ghost opened this issue Nov 11, 2015 · 1 comment

Comments

@ghost
Copy link

ghost commented Nov 11, 2015

The puppet agent normally logs all changes to the syslog. This is very handy for most situations, however, it is not desirable to have puppet log the changes on secrets like passwords or pre-shared keys.

At present the duo_unix module does not prevent this from happening and the ikey and skey values are logged to syslog. The show_diff metaparameter can prevent it from being recorded in the logs.

The file resource type can accept the show_diff metaparameter:
https://docs.puppetlabs.com/references/latest/type.html#file-attributes

@petems
Copy link

petems commented Aug 22, 2016

This can also be done with the new Sensitive type in Puppet 4.6! 👍

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant