Bug 787884

Summary: printing to EL6 CUPS server by authenticated IPP fails
Product: [Fedora] Fedora Reporter: Aram Agajanian <agajania>
Component: cupsAssignee: Tim Waugh <twaugh>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 16CC: devurandom, jpopelka, miturria, twaugh
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-02-13 23:51:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Aram Agajanian 2012-02-07 00:52:00 UTC
Description of problem:
I have configured a printer in CUPS on RHEL6.2 which accepts SSL connections on port 7631 and requires authentication.  I have been using this printer configuration for about a year.  In the past, I have configured this printer with the following URL:

ipp://servername:7631?encryption=always

I am unable to print to this CUPS server from Fedora 16.  If I try to use the above URL, I see an error message on the Fedora CUPS server.

If I use a ipp:// URL or an ipps:// URL without encryption=always, the Feodra CUPS server fails to negotiate an SSL connection with the EL6 CUPS server.

If I use an https:// URL, then the SSL connection seems to work, but I get the following error in the EL6 CUPS server error_log file:

D [06/Feb/2012:19:42:05 -0500] Connection from 137.140.15.4 now encrypted.
D [06/Feb/2012:19:42:05 -0500] cupsdReadClient: 11 POST / HTTP/1.1
D [06/Feb/2012:19:42:05 -0500] cupsdSetBusyState: Active clients
D [06/Feb/2012:19:42:05 -0500] cupsdAuthorize: No authentication data provided.
D [06/Feb/2012:19:42:05 -0500] cupsdIsAuthorized: username=""
D [06/Feb/2012:19:42:05 -0500] cupsdSendHeader: 11 WWW-Authenticate: Basic realm="CUPS"
D [06/Feb/2012:19:42:05 -0500] cupsdCloseClient: 11
D [06/Feb/2012:19:42:05 -0500] SSL shutdown successful!
D [06/Feb/2012:19:42:05 -0500] cupsdSetBusyState: Not busy
E [06/Feb/2012:19:42:05 -0500] Bad request line "����zɁ��sj�aH�u|x��m!6Ҙ���?TP��9�����MiB�+l ��8�1{� $��(߱�2I�{g��G~�`I��=��" from 137.140.4.15!
D [06/Feb/2012:19:42:05 -0500] cupsdCloseClient: 11

I also see "Unable to get printer status." on the Fedora CUPS server.

Version-Release number of selected component (if applicable):
1:1.5.0-22.fc16

How reproducible:
Happens every time.

Steps to Reproduce:
1. Configure a printer to print to authenticated EL6 CUPS server.  I did this with system-configure-printer and then changed the URL in printers.conf with a text editor.
  
Actual results:
The Fedora 16 CUPS server cannot communicate with the EL6 CUPS server.

Expected results:
The Fedora 16 CUPS server should be able to communicate with the EL6 CUPS server.

Comment 1 Tim Waugh 2012-05-02 16:21:36 UTC
*** Bug 816591 has been marked as a duplicate of this bug. ***

Comment 2 Jiri Popelka 2012-05-04 10:39:14 UTC
(In reply to comment #0)
> I have configured a printer in CUPS on RHEL6.2 which accepts SSL connections on
> port 7631 and requires authentication.
> ...
> E [06/Feb/2012:19:42:05 -0500] Bad request line
> "����zɁ��sj�aH�u|x��m!6Ҙ���?TP��9�����MiB�+l ��8�1{�
> $��(߱�2I�{g��G~�`I��=��" from 137.140.4.15!

Seems like http://www.cups.org/str.php?L3288

Could you attach your cupsd.conf ?

Comment 5 Dennis Schridde 2012-05-04 13:09:13 UTC
(In reply to comment #2)
> Could you attach your cupsd.conf ?
See for example attachment #580471 [details] from bug #816591.

Comment 6 Dennis Schridde 2012-05-04 13:13:45 UTC
Also note bug #816591 comment #0 (excerpt, highlights by me):
"When we try to print *from* a Fedora 16 *or SL 6.2* machine on a CUPS server
running on a SL 6.2 server"

So this does not seem to be exclusive to F16.

Comment 7 Dennis Schridde 2012-05-08 09:10:49 UTC
The same thing happens when trying to print from a Gentoo/Linux system using GIMP 2.8: Quickly after opening the print dialogue the server's error_log is spammed with garbage.

Here the client.conf contains "ServerName localhost:6310" for SSH tunnelling.

Comment 8 Fedora End Of Life 2013-01-16 20:27:49 UTC
This message is a reminder that Fedora 16 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 16. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '16'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 16's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 16 is end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" and open it against that version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 9 Fedora End Of Life 2013-02-13 23:51:29 UTC
Fedora 16 changed to end-of-life (EOL) status on 2013-02-12. Fedora 16 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.