Bug 1321891 - DES to AES password conversion fails if a backend is empty
Summary: DES to AES password conversion fails if a backend is empty
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: 389-ds-base
Version: 7.3
Hardware: All
OS: Linux
Target Milestone: rc
: ---
Assignee: Noriko Hosoi
QA Contact: Viktor Ashirov
Petr Bokoc
Depends On: 1320715
TreeView+ depends on / blocked
Reported: 2016-03-29 10:37 UTC by Marcel Kolaja
Modified: 2019-10-10 11:42 UTC (History)
8 users (show)

Fixed In Version: 389-ds-base-
Doc Type: Bug Fix
Doc Text:
During the upgrade from Red Hat Enterprise Linux 7.1 to 7.2, the encryption algorithm used by the Reversible Password Plug-in was changed from DES to AES, and 389-ds-base automatically converted all passwords to the new algorithm upon upgrade. However, password conversion failed with an "error 32" if any defined backend was missing the top entry. Additionally, even if the conversion failed, 389-ds-base still disabled the DES plug-in, which caused existing passwords to fail to decode. This bug has been fixed, 389-ds-base now ignores errors when searching backends for passwords to convert, and the DES plug-in is now only disabled after all passwords using the DES algorithm were successfully converted to AES.
Clone Of: 1320715
Last Closed: 2016-05-12 09:59:24 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:1048 0 normal SHIPPED_LIVE 389-ds-base bug fix update 2016-05-12 13:54:32 UTC

Description Marcel Kolaja 2016-03-29 10:37:19 UTC
This bug has been copied from bug #1320715 and has been proposed
to be backported to 7.2 z-stream (EUS).

Comment 5 Viktor Ashirov 2016-04-11 08:57:51 UTC
Build tested: 389-ds-base-
platform linux2 -- Python 2.7.5, pytest-2.9.1, py-1.4.31, pluggy-0.3.1 -- /usr/bin/python
cachedir: tickets/.cache
rootdir: /export/tests/tickets, inifile: 
plugins: html-1.8.0, xdist-1.14, cov-2.2.1, catchlog-1.2.2, flake8-0.2
collected 2 items 

tickets/ticket47462_test.py::test_ticket47462 PASSED
tickets/ticket47462_test.py::test_ticket47462_final PASSED

Marking as VERIFIED.

Comment 6 Petr Bokoc 2016-04-20 11:44:07 UTC
Hello Noriko, can you please check the Doc Text and let me know if it's correct?


Comment 7 Noriko Hosoi 2016-04-20 15:56:48 UTC
(In reply to Petr Bokoc from comment #6)
> Hello Noriko, can you please check the Doc Text and let me know if it's
> correct?
> Thanks,
> Petr

Hi Petr,
The Doc Text is very well written.  Thanks!  You have my ack.

Comment 9 errata-xmlrpc 2016-05-12 09:59:24 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.