Bug 1129413 - installer should ask user to input password twice
Summary: installer should ask user to input password twice
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: JBoss Operations Network
Classification: JBoss
Component: Installer
Version: JON 3.3.0
Hardware: All
OS: All
unspecified
low
Target Milestone: ER04
: JON 3.3.0
Assignee: John Mazzitelli
QA Contact: Armine Hovsepyan
URL:
Whiteboard:
Depends On: 1141181
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-08-12 17:18 UTC by Viet Nguyen
Modified: 2015-09-03 00:03 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-12-11 14:02:35 UTC
Type: Bug


Attachments (Terms of Use)
password_confirmation (212.66 KB, image/png)
2014-10-14 08:34 UTC, Armine Hovsepyan
no flags Details

Description Viet Nguyen 2014-08-12 17:18:44 UTC
Description of problem:

User is now asked visually confirm encoded auto-install password with a yes/no question which is not really easy to do because it's long (try this  OFj2IjCsPJFfMAxmQxLGPw== :)  Most password tools ask user to input the password twice.

Version-Release number of selected component (if applicable):
3.3.DR01

Comment 1 Jay Shaughnessy 2014-08-25 19:42:13 UTC
It's not asking you to type in an encoded password, it's asking for plain text.  So I think this is OK since you can see what you just typed.

I'll close this, feel free to re-open if you feel there is still a problem.

Comment 2 Viet Nguyen 2014-08-25 20:41:43 UTC
Clarification: I was confused about the usage. User is actually asked to input *clear text* password, not obfuscated. It is still a good idea to type the password twice.

Comment 3 John Mazzitelli 2014-09-18 20:19:09 UTC
this is going to be addressed with the fix to bug #1141181 - I'm reopening this and will track it along with that BZ

Comment 4 John Mazzitelli 2014-09-18 20:53:35 UTC
commit 07151ddb23e6065d5a72ae900b1cbf420b00e27c
Author: John Mazzitelli <mazz@redhat.com>
Date:   Thu Sep 18 16:51:51 2014 -0400

    BZ 1141181 1129413 - don't echo passwords to the console. ask to confirm passwords

Comment 5 John Mazzitelli 2014-09-18 20:55:27 UTC
commit b5b0e2d18e33b921f4bf57454179efd1707f1a9f
Author: John Mazzitelli <mazz@redhat.com>
Date:   Thu Sep 18 16:51:51 2014 -0400

    BZ 1141181 1129413 - don't echo passwords to the console. ask to confirm passwords
    (cherry picked from commit 07151ddb23e6065d5a72ae900b1cbf420b00e27c)

Comment 6 Simeon Pinder 2014-10-01 21:33:06 UTC
Moving to ON_QA as available for test with build:
https://brewweb.devel.redhat.com/buildinfo?buildID=388959

Comment 7 Armine Hovsepyan 2014-10-14 08:34:28 UTC
Created attachment 946733 [details]
password_confirmation

Comment 8 Armine Hovsepyan 2014-10-14 08:34:47 UTC
verified in JON 3.3 ER04
screen-shot attached


Note You need to log in before you can comment on or make changes to this bug.