| Summary: | ssh login to an account using ecryptfs Private pam mount results in dead lock and more | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Piergiorgio Sartor <piergiorgio.sartor> |
| Component: | ecryptfs-utils | Assignee: | Michal Hlavinka <mhlavink> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | urgent | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 15 | CC: | esandeen, jchadima, mhlavink, tmraz |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | i686 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | ecryptfs-utils-87-6.fc14 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-08-03 22:53:04 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Piergiorgio Sartor
2011-07-15 11:17:52 UTC
I know about this, it's because ecryptfs pam module uses ugly hacks, because we need to get password retrieved in authentication stage (included in user's keyring) to (survive till) create session stage. If we don't use those ugly hacks, keyring does not contain any data when we need them. Unfortunately, there is no known solution yet. Well at least it should not make the user session to have gid==0 and no gid ecryptfs. IMO this needs to be fixed in pam_ecryptfs at least partially. The module should not in any circumstance do the above - it should fail regularly if the authentication is done in other process than the session. This bug in ecryptfs may lead to security related issues. The gid 0 may give to the user undesired privilegies. Please resolve this bug ASAP. ecryptfs-utils-87-5.fc14 has been submitted as an update for Fedora 14. https://admin.fedoraproject.org/updates/ecryptfs-utils-87-5.fc14 ecryptfs-utils-87-6.fc15 has been submitted as an update for Fedora 15. https://admin.fedoraproject.org/updates/ecryptfs-utils-87-6.fc15 Package ecryptfs-utils-87-7.fc15: * should fix your issue, * was pushed to the Fedora 15 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing ecryptfs-utils-87-7.fc15' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/ecryptfs-utils-87-7.fc15 then log in and leave karma (feedback). ecryptfs-utils-87-7.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report. ecryptfs-utils-87-6.fc14 has been pushed to the Fedora 14 stable repository. If problems still persist, please make note of it in this bug report. |