Browse code

Delete the default guest user from rabbitmq

Leaving the default user enabled is a security issue, as it can be used
without credentials. It also may mask issues like seen in [1].

[1] https://bugs.launchpad.net/bugs/1651576

Change-Id: I75b4e5696c0f8017b869127a10f3c14e2f8bd121

Jens Harbott authored on 2017/08/29 18:52:58
Showing 1 changed files
... ...
@@ -97,6 +97,8 @@ function restart_rpc_backend {
97 97
 
98 98
             break
99 99
         done
100
+        # NOTE(frickler): Remove the default guest user
101
+        sudo rabbitmqctl delete_user guest || true
100 102
     fi
101 103
 }
102 104