Bug 1145382
| Summary: | Bad manipulation of passwordhistory | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Noriko Hosoi <nhosoi> |
| Component: | 389-ds-base | Assignee: | Noriko Hosoi <nhosoi> |
| Status: | CLOSED ERRATA | QA Contact: | Viktor Ashirov <vashirov> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.0 | CC: | amsharma, nkinder, rmeggins |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | 389-ds-base-1.3.4.0-1.el7 | Doc Type: | Bug Fix |
| Doc Text: |
If a value of password policy attribute (e.g., passwordhistory) is accidentally deleted, it causes a null reference and crashes the server.
The null reference was fixed.
Even if a value of password policy attribute is deleted, the server does not crash.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-11-19 11:42:07 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Noriko Hosoi
2014-09-23 01:09:29 UTC
For the reproducer/verification steps, see this original bug. https://bugzilla.redhat.com/show_bug.cgi?id=1145072 [root@dhcp201-167 ~]# ldapmodify -p 389 -h localhost -D 'cn=Directory Manager' -w Secret123 -a << EOF > dn: uid=tuser,ou=People,dc=example,dc=com > objectClass: inetorgperson > objectClass: organizationalPerson > objectClass: person > objectClass: top > uid: tuser > sn: tuser > cn: test user > userPassword: Secret123 > EOF adding new entry "uid=tuser,ou=People,dc=example,dc=com" [root@dhcp201-167 ~]# ldapmodify -p 389 -h localhost -D 'cn=Directory Manager' -w Secret123 << EOF > dn: cn=config > changetype: modify > replace: nsslapd-pwpolicy-local > nsslapd-pwpolicy-local: on > - > replace: passwordChange > passwordChange: on > - > replace: passwordHistory > passwordHistory: on > - > EOF modifying entry "cn=config" [root@dhcp201-167 ~]# ldapmodify -p 389 -h localhost -D 'uid=tuser,ou=People,dc=example,dc=com' -w Secret123 << EOF > dn: uid=tuser,ou=People,dc=example,dc=com > changetype: modify > replace: userpassword > userpassword: new > EOF modifying entry "uid=tuser,ou=People,dc=example,dc=com" [root@dhcp201-167 ~]# ldapsearch -LLL -p 389 -h localhost -D 'cn=Directory Manager' -w Secret123 -b uid=tuser,ou=People,dc=example,dc=com passwordhistory dn: uid=tuser,ou=People,dc=example,dc=com passwordhistory: 20150907122309Z{SSHA}VA1V5pXurBNskOvlqv/LXJQFsDZbIGXQ1ngQtg== [root@dhcp201-167 ~]# ldapmodify -p 389 -h localhost -D 'cn=Directory Manager' -w Secret123 << EOF > dn: uid=tuser,ou=People,dc=example,dc=com > changetype: modify > replace: passwordhistory > passwordHistory: > EOF modifying entry "uid=tuser,ou=People,dc=example,dc=com" [root@dhcp201-167 ~]# ldapmodify -p 389 -h localhost -D 'uid=tuser,ou=People,dc=example,dc=com' -w new << EOF > dn: uid=tuser,ou=People,dc=example,dc=com > changetype: modify > replace: userpassword > userpassword: crash > EOF modifying entry "uid=tuser,ou=People,dc=example,dc=com" [root@dhcp201-167 ~]# pgrep ns-slapd 29730 [root@dhcp201-167 ~]# rpm -qa | grep 389 389-ds-base-devel-1.3.4.0-15.el7.x86_64 389-ds-base-libs-1.3.4.0-15.el7.x86_64 389-ds-base-1.3.4.0-15.el7.x86_64 389-ds-base-debuginfo-1.3.4.0-15.el7.x86_64 HENCE VERIFIED. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-2351.html |