Bug 119651 - HTTP authentication against password file with SHA1 password hashes fails
HTTP authentication against password file with SHA1 password hashes fails
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: httpd (Show other bugs)
3.0
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Joe Orton
:
Depends On:
Blocks: 116727
  Show dependency treegraph
 
Reported: 2004-03-31 23:14 EST by Espen Carlsen
Modified: 2007-11-30 17:07 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-08-17 22:55:39 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Espen Carlsen 2004-03-31 23:14:39 EST
After upgrade from Redhat 7.3 to RedHat Enterprise 3, none of the 
users can authenticate with the webserver.

Steps to reproduce:
Create htpassword file with a user and password encrypted with MD5
Try to authenticate
Authentication works
Alter encrytion of the same user to crypt
Try to authenticate
Authentication works
Alter encryption of the same user to SHA-1
Try to authenticate
Authentication fails.
Error log reports:
[Wed Mar 31 16:12:17 2004] [error] [client 192.168.66.234] user 
testuser: authentication failure for "/party/admin/new": Password 
Mismatch.

The workaround may be to convert all passwords to MD5, but since I 
don't have a list over all the users passwords this is not an option.
Comment 1 Joe Orton 2004-04-01 06:33:33 EST
Thanks for the report.  This is a regression in 2.0, we can make fixed
packages available for testing shortly.
Comment 2 Joe Orton 2004-04-01 08:46:46 EST
Packages which include the fix for this issue are now available for
testing purposes from: http://people.redhat.com/jorton/Taroon-httpd/.
 The fix will be included in future httpd updates for RHEL3.
Comment 3 Espen Carlsen 2004-04-01 11:49:15 EST
The test packages sovled my problem.
Thanx!
Comment 4 Jay Turner 2004-08-17 22:55:39 EDT
Closing out based on feedback from original reporter.
Comment 5 Josh Bressers 2004-09-01 14:55:40 EDT
An errata has been issued which should help the problem 
described in this bug report. This report is therefore being 
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, 
please follow the link below. You may reopen this bug report 
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2004-349.html

Note You need to log in before you can comment on or make changes to this bug.