Bug 53855 - Insecure login to www.redhat.com/bugzilla using Netscape on RH Linux 7.1
Summary: Insecure login to www.redhat.com/bugzilla using Netscape on RH Linux 7.1
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Bugzilla
Classification: Community
Component: Bugzilla General
Version: 2.8
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: David Lawrence
QA Contact: David Lawrence
URL: http://www.redhat.com/bugzilla/login.cgi
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2001-09-19 23:17 UTC by Mark Harig
Modified: 2007-04-18 16:37 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2003-04-02 23:36:06 UTC
Embargoed:


Attachments (Terms of Use)

Description Mark Harig 2001-09-19 23:17:27 UTC
From Bugzilla Helper:
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)

Description of problem:
When I attempt to login to www.redhat.com/bugzilla using Netscape 4.x on 
RH Linux 7.1, a warning is issued: "The information you submit is insecure 
and could be observed by a third party while in transit.  If you are 
submitting passwords, credit card numbers, or other information that you 
would like to keep private, it would be safer for you to cancel the 
submission."

Is it OK for RedHat's bugzilla passwords to be transmitted as clear text?


Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1. Start Netscape in RH Linux 7.1
2. Open the web page www.redhat.com/bugzilla
3. Click on login, and enter your login ID and password.
4. Click on the 'Login' button.  The warning message is displayed.
	

Actual Results:  The warning message about the insecure transfer of a 
login ID and password is displayed.

Expected Results:  An encrypted transfer of the bugzilla user's login ID 
and password should be performed.

Additional info:

Comment 1 David Lawrence 2001-09-19 23:29:31 UTC
I need to have them remove that redirect from the main web site as it causes
confusion. But it is not necessarily a bug. If you go directly to 

http://bugzilla.redhat.com/bugzilla 

you will still get the error about passing insecure information since the
channel is not encrypted. You can connect to bugzilla securely by using the
following url instead

https://bugzilla.redhat.com/bugzilla
This should be more secure. I will speak with the web guys to make sure this is
the default or the redirect is removed altogether.

Comment 2 Kjartan Maraas 2003-04-02 22:25:42 UTC
Still not using https as the default, right?

Comment 3 Mark Harig 2003-04-02 22:42:07 UTC
>
> Still not using https as the default, right?
>

It appears to be using https as the default for me now when I click on the "Red 
Hat Network" link in Mozilla (after loading the redhat.com web page).

As far as I can tell, this bug has been fixed.


Comment 4 David Lawrence 2003-04-02 23:36:06 UTC
Should be the default. If you find an entry point for logging in that doesnt use
https please reopen this and let me know.


Note You need to log in before you can comment on or make changes to this bug.