As a user, I can rest easy in the knowledge that my celery workers will ensure that their AMQP messages are signed by a trusted sender
We should configure Pulp to use Celery's message signing feature. This will add a layer of security to protect the Celery workers from performing tasks that might have been injected by an attacker.Deliverables:Pulp server can be configured to sign messagesPulp workers can be configured to require valid signatures on messagesDocument how users can configure message signing http://celery.readthedocs.org/en/latest/userguide/security.html#message-signing
Updated by bmbouter over 3 years ago
Pulp 2 is approaching maintenance mode, and this Pulp 2 ticket is not being actively worked on. As such, it is being closed as WONTFIX. Pulp 2 is still accepting contributions though, so if you want to contribute a fix for this ticket, please reopen or comment on it. If you don't have permissions to reopen this ticket, or you want to discuss an issue, please reach out via the developer mailing list.