Bug 3077 - smb print user's password stored in world-readable plaintext
smb print user's password stored in world-readable plaintext
Product: Red Hat Linux
Classification: Retired
Component: printtool (Show other bugs)
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: David Lawrence
: Security
Depends On:
  Show dependency treegraph
Reported: 1999-05-26 18:33 EDT by George Karabin
Modified: 2008-05-01 11:37 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 1999-06-08 14:51:40 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description George Karabin 1999-05-26 18:33:32 EDT
I have my machine configured to print to a print server
running on a Windows box. The password for the Windows
domain account that is used for printing appears to be
stored in plaintext in the following file, which is world

-r-xr--r--   1 root     root           83 May 24 09:22

I believe that this file is created by the printtool
package, but I haven't investigated very much.

It seems that the password ought to be encrypted no matter
what, and if there is no reason to leave it world readable,
I'd change the permissions from 0544 to 0540.
Comment 1 David Lawrence 1999-06-08 14:51:59 EDT
This may be changed for the next release but is not designed to be
used with the same username and password as a real linux account. A
warning message is generated from printtool explaining this when a SMB
printer is created. Please create a dummy account on the print server
for print jobs from the Linux box to be sent to so real user names and
passwords have to be used.

Note You need to log in before you can comment on or make changes to this bug.