Bug 492090
Summary: | passwords stored in world readable file | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Tom Horsley <horsley1953> |
Component: | pptp | Assignee: | Paul Howarth <paul> |
Status: | CLOSED NEXTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 10 | CC: | paul |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | 1.7.2-5.fc10 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-04-09 16:15:50 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tom Horsley
2009-03-25 11:31:20 UTC
This problem only occurs if you use "pptpsetup --delete ..." The out of the box state for /etc/ppp/chap-secrets is that it's owned by root and mode 0600, which is fine (the file originates from the ppp package). Running "pptpsetup --create ..." does not change this: # ls -l /etc/ppp/chap-secrets -rw------- 1 root root 278 2006-04-03 17:56 /etc/ppp/chap-secrets # pptpsetup --create test --server 1.2.3.4 --username noddy --password bigears # ls -l /etc/ppp/chap-secrets -rw------- 1 root root 332 2009-03-25 12:25 /etc/ppp/chap-secrets However, "pptpsetup --delete ..." replaces the file and uses the wrong permissions: # pptpsetup --delete test # ls -l /etc/ppp/chap-secrets -rw-r--r-- 1 root root 278 2009-03-25 12:26 /etc/ppp/chap-secrets So this is something I need to fix. Regarding the best way to do things, I believe the upstream recommendation is to use NetworkManager-pptp rather than pptpsetup. Yep, I did use --delete when I was initially experimenting with the setup. pptp-1.7.2-5.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/pptp-1.7.2-5.fc10 pptp-1.7.2-5.fc10 has been pushed to the Fedora 10 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update pptp'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F10/FEDORA-2009-3070 Note that this update is designed to retain the existing permissions on /etc/ppp/chap-secrets so you'll need to restore the permissions to the standard 0600 before testing. # chmod 0600 /etc/ppp/chap-secrets pptp-1.7.2-5.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. |