OpenStack Horizon - password_autocomplete parameter set to off

Information

Common feature that applications use to provide users a convenience is to cache the password locally in the browser (on the client machine) and having it 'pre-typed' in all subsequent requests. While this feature can be perceived as extremely friendly for the average user, at the same time, it introduces a flaw, as the user account becomes easily accessible to anyone that uses the same account on the client machine and thus may lead to compromise of the user account.

Solution

Set the value of parameter password_autocomplete in /etc/openstack-dashboard/local_settings.py to off

See Also

http://docs.openstack.org/security-guide/dashboard/checklist.html

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 118e45db9bd936937da778ff76ca5a115d41eab907de754834e97c21d017df77