Bug 234386
Summary: | Curly braces placed in passwords changed via RHN prevent users from logging in. | ||
---|---|---|---|
Product: | Red Hat Satellite 5 | Reporter: | Alex Wood <awood> |
Component: | Usability | Assignee: | John Sanda <jsanda> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Mark Sechrest <msechres> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | duffy, inode0 |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | 5.0.3 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-10-02 16:37:46 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 246409 |
Description
Alex Wood
2007-03-28 20:17:24 UTC
Let's check to be sure our LDAP interface is properly encoding. Maybe updating via triggers is taking a different path? This is a RHN bug. RHN seems to be stripping off characters without telling the user. Example: https://rhn.webqa.redhat.com/rhn/account/UserDetails.do change password to {{{test123{} test123 gets sent. Also, if you change it to {{{test123 with a confirmation of test123 it will match. SSO error message states: Password must be ASCII and cannot contain the following special characters (") (<) (>) (space) Checked in revision 117674. Disabled the logic that scrubs the password field. Added logic to check the password for illegal characters. Test Plan: Update your password 1. Log into RHN and go to https://rhn.webqa.redhat.com/rhn/account/UserDetails.do. 2. Update your password to include one or more of the characters (delimited by parens) in Comment 3. 3. Verify that you are sent back UserDetails.do and an error message is displayed that says the characters from Comment 3 are illegal. 4. Enter a new password without any illegal characters but includes a curly brace. 5. Submit the form, logout and verify that you can log back in. Extensions: 1.a Update another user's password 1. Go to https://rhn.webqa.redhat.com/rhn/users/ActiveList.do. 2. Select a user other than yourself. 3. Repeat steps 2 through 5 from above. Mark, Please verify on your end, but RHN seems to be stopping users from entering ",<,> and the space character |