Bug 1253498

Summary: ipa vault-add does not check type for password and public-key related arguments
Product: Red Hat Enterprise Linux 7 Reporter: Scott Poore <spoore>
Component: ipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED DUPLICATE QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.2CC: pvoborni, rcritten
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-14 08:07:21 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Scott Poore 2015-08-13 20:54:56 UTC
Description of problem:

It looks like vault-add does not restrict use of arguments by type.  I confirmed with Endi that the password/public-key related arguments do nothing for vaults that don't match their type (symmetric/asymmetric).  So, the command line should show an error.

[root@master ~]# ipa vault-add vname --password=SomePa55w0rd
-------------------
Added vault "vname"
-------------------
  Vault name: vname
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-archive vname --in=/tmp/secret.in
--------------------------------
Archived data into vault "vname"
--------------------------------
[root@master ~]# ipa vault-retrieve vname
---------------------------------
Retrieved data from vault "vname"
---------------------------------
  Data: dGVzdF9kYXRhMgo=
[root@master ~]# echo dGVzdF9kYXRhMgo=|base64 -d
test_data2
[root@master ~]# ipa vault-add vname_password --password-file=/tmp/stdin.in 
----------------------------
Added vault "vname_password"
----------------------------
  Vault name: vname_password
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-add vname_publickey --public-key-file=public.pem 
-----------------------------
Added vault "vname_publickey"
-----------------------------
  Vault name: vname_publickey
  Type: standard
  Owner users: admin


Version-Release number of selected component (if applicable):
ipa-server-4.2.0-4.el7.x86_64

How reproducible:
always

Steps to Reproduce:
1.  ipa-server-install
2.  ipa-kra-install
3.  kinit admin
4.  ipa vault-add --password="something"
5.  ipa vault-add --public-key="somepkblob"
...

Actual results:
arguments excepted but not used.  instead should error that the args don't match the type

Expected results:
arguments would only be allowed if used by the type

Additional info:

Comment 2 Scott Poore 2015-08-14 01:13:37 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/5213

Comment 3 Petr Vobornik 2015-08-14 08:07:21 UTC
duplicate/ fixed in bug 1251561 , see https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=7d7ffb62526595433412633c05af5af7909124c8

*** This bug has been marked as a duplicate of bug 1251561 ***