Bug 1253498 - ipa vault-add does not check type for password and public-key related arguments
ipa vault-add does not check type for password and public-key related arguments
Status: CLOSED DUPLICATE of bug 1251561
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: IPA Maintainers
Namita Soman
Depends On:
  Show dependency treegraph
Reported: 2015-08-13 16:54 EDT by Scott Poore
Modified: 2015-08-14 04:07 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-08-14 04:07:21 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Scott Poore 2015-08-13 16:54:56 EDT
Description of problem:

It looks like vault-add does not restrict use of arguments by type.  I confirmed with Endi that the password/public-key related arguments do nothing for vaults that don't match their type (symmetric/asymmetric).  So, the command line should show an error.

[root@master ~]# ipa vault-add vname --password=SomePa55w0rd
Added vault "vname"
  Vault name: vname
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-archive vname --in=/tmp/secret.in
Archived data into vault "vname"
[root@master ~]# ipa vault-retrieve vname
Retrieved data from vault "vname"
  Data: dGVzdF9kYXRhMgo=
[root@master ~]# echo dGVzdF9kYXRhMgo=|base64 -d
[root@master ~]# ipa vault-add vname_password --password-file=/tmp/stdin.in 
Added vault "vname_password"
  Vault name: vname_password
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-add vname_publickey --public-key-file=public.pem 
Added vault "vname_publickey"
  Vault name: vname_publickey
  Type: standard
  Owner users: admin

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.  ipa-server-install
2.  ipa-kra-install
3.  kinit admin
4.  ipa vault-add --password="something"
5.  ipa vault-add --public-key="somepkblob"

Actual results:
arguments excepted but not used.  instead should error that the args don't match the type

Expected results:
arguments would only be allowed if used by the type

Additional info:
Comment 2 Scott Poore 2015-08-13 21:13:37 EDT
Upstream ticket:
Comment 3 Petr Vobornik 2015-08-14 04:07:21 EDT
duplicate/ fixed in bug 1251561 , see https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=7d7ffb62526595433412633c05af5af7909124c8

*** This bug has been marked as a duplicate of bug 1251561 ***

Note You need to log in before you can comment on or make changes to this bug.