Bug 111519

Summary: password requirements while registering are too strict
Product: Red Hat Enterprise Linux 3 Reporter: Josh Kelley <joshkel>
Component: up2dateAssignee: Bret McMillan <bretm>
Status: CLOSED WONTFIX QA Contact: Fanny Augustin <fmoquete>
Severity: medium Docs Contact:
Priority: medium    
Version: 3.0   
Target Milestone: ---   
Target Release: ---   
Hardware: athlon   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-10-19 19:32:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 120092    

Description Josh Kelley 2003-12-04 20:13:28 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.5)
Gecko/20031007

Description of problem:
While trying to register a new system under an existing account using
up2date, I enter my username and password and get the following error:

Error message:
   password contains character `"'
Error Class Code: 15
Error Class Info: The username contains invalid characters.

Three problems:
1. Up2date should accept a wider range of characters in passwords to
permit more secure passwords.
2. Up2date should at least accept the same range of characters for
passwords that the RHN and RedHat web sites accept when setting passwords.
3. The Error Class Info is not correct; the problem is with the
password, not the username.


Version-Release number of selected component (if applicable):
up2date-4.0.1-1

How reproducible:
Always

Steps to Reproduce:
1. From the RHN web site, change the account password to include a ".
2. Run up2date to register a new system with RHN.
3. Enter the username and password for the account from step 1.

    

Actual Results:  Error message:
   password contains character `"'

Expected Results:  Successful registration.

Additional info:

Comment 1 RHEL Program Management 2007-10-19 19:32:25 UTC
This bug is filed against RHEL 3, which is in maintenance phase.
During the maintenance phase, only security errata and select mission
critical bug fixes will be released for enterprise products. Since
this bug does not meet that criteria, it is now being closed.
 
For more information of the RHEL errata support policy, please visit:
http://www.redhat.com/security/updates/errata/
 
If you feel this bug is indeed mission critical, please contact your
support representative. You may be asked to provide detailed
information on how this bug is affecting you.