Bug 595694 - Satellite sends misleading error message when wrong login/password is sent during registration
Satellite sends misleading error message when wrong login/password is sent du...
Status: CLOSED DEFERRED
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Registration (Show other bugs)
530
All Linux
low Severity low
: ---
: ---
Assigned To: Michael Mráka
Red Hat Satellite QA List
:
Depends On:
Blocks: 462714
  Show dependency treegraph
 
Reported: 2010-05-25 07:55 EDT by Michael Mráka
Modified: 2014-07-04 09:26 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-07-04 09:26:56 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Michael Mráka 2010-05-25 07:55:09 EDT
Description of problem:
Satellite returns misleading error messages sometimes containing security sensitive information (e.g. account exists).

Version-Release number of selected component (if applicable):
spacewalk-backend-0.5.28-34.el5sat.noarch

How reproducible:
always

Steps to Reproduce:
1. run rhn_register
2. click through to 'Choose an update location' page
3. check 'Red Hat Network Satellite' and fill address of an existing satellite 5.3
4. fill wrong username/password and click Forward


Actual results:
depending whether username exists on satellite and password length error window says
 Error Class Code: 3
 Error Class Info: This login is already taken, or the password is incorrect.
or
 There was an error while logging in....
 and /var/log/up2date contains
  up2date_client.up2dateErrors.PasswordMinLengthError:
  Error Message:
    password must be at least 5 characters
or
 Error Class Code: 2001
 Error Class Info: 
     RHN Satellite user creation is not allowed via rhn_register...

Expected results:
The same error message which Hosted sends, i.e.
Error Class Code: 3
Error Class Info: The login or password is incorrect.

Additional info:
This is more generally about removing old register_user, new_user, etc. stuff which Hosted removed some time ago.

Note You need to log in before you can comment on or make changes to this bug.