Bug 1253498 - ipa vault-add does not check type for password and public-key related arguments
ipa vault-add does not check type for password and public-key related arguments
Status: CLOSED DUPLICATE of bug 1251561
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.2
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: IPA Maintainers
Namita Soman
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-08-13 16:54 EDT by Scott Poore
Modified: 2015-08-14 04:07 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-14 04:07:21 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Scott Poore 2015-08-13 16:54:56 EDT
Description of problem:

It looks like vault-add does not restrict use of arguments by type.  I confirmed with Endi that the password/public-key related arguments do nothing for vaults that don't match their type (symmetric/asymmetric).  So, the command line should show an error.

[root@master ~]# ipa vault-add vname --password=SomePa55w0rd
-------------------
Added vault "vname"
-------------------
  Vault name: vname
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-archive vname --in=/tmp/secret.in
--------------------------------
Archived data into vault "vname"
--------------------------------
[root@master ~]# ipa vault-retrieve vname
---------------------------------
Retrieved data from vault "vname"
---------------------------------
  Data: dGVzdF9kYXRhMgo=
[root@master ~]# echo dGVzdF9kYXRhMgo=|base64 -d
test_data2
[root@master ~]# ipa vault-add vname_password --password-file=/tmp/stdin.in 
----------------------------
Added vault "vname_password"
----------------------------
  Vault name: vname_password
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-add vname_publickey --public-key-file=public.pem 
-----------------------------
Added vault "vname_publickey"
-----------------------------
  Vault name: vname_publickey
  Type: standard
  Owner users: admin


Version-Release number of selected component (if applicable):
ipa-server-4.2.0-4.el7.x86_64

How reproducible:
always

Steps to Reproduce:
1.  ipa-server-install
2.  ipa-kra-install
3.  kinit admin
4.  ipa vault-add --password="something"
5.  ipa vault-add --public-key="somepkblob"
...

Actual results:
arguments excepted but not used.  instead should error that the args don't match the type

Expected results:
arguments would only be allowed if used by the type

Additional info:
Comment 2 Scott Poore 2015-08-13 21:13:37 EDT
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/5213
Comment 3 Petr Vobornik 2015-08-14 04:07:21 EDT
duplicate/ fixed in bug 1251561 , see https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=7d7ffb62526595433412633c05af5af7909124c8

*** This bug has been marked as a duplicate of bug 1251561 ***

Note You need to log in before you can comment on or make changes to this bug.