Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 5 product line. The current stable release is 5.10. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 641029

Summary: RFE: allow using `rhn-channel' without having to enter the password on the command line
Product: Red Hat Enterprise Linux 5 Reporter: Radek Bíba <rbiba>
Component: rhn-client-toolsAssignee: Miroslav Suchý <msuchy>
Status: CLOSED ERRATA QA Contact: Martin Minar <mminar>
Severity: medium Docs Contact:
Priority: low    
Version: 5.6CC: jhutar, mkoci, mminar, msuchy, pwouters
Target Milestone: rcKeywords: FutureFeature
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rhn-client-tools-0.4.20-48.el5 Doc Type: Enhancement
Doc Text:
Previously, when changing a channel subscription, the rhn-channel program accepted a username and a password only as parameters on the command line. As a consequence, other people could have read personal data. Now, users are prompted for the username and the password if they are not entered as parameters.
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-07-21 07:08:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Radek Bíba 2010-10-07 15:18:52 UTC
Description of problem:
rhn-channel needs a valid user name and password to change channel subscriptions. Currently it can only accept them on the command line, together with other parameters. Would it be possible to add an interactive mode that would save users from entering their password on the command line, making it invisible to anyone looking over their shoulder / watching their presentation / reading their bash history? Would be nice if the password could be read from standard input, too.

Version-Release number of selected component (if applicable):
rhn-client-tools-0.4.20-33.el5_5.2 / rhn-setup-0.4.20-33.el5_5.2

Comment 1 Miroslav Suchý 2011-01-21 12:44:17 UTC
Already fixed in Spacewalk.git in commit aed727e46acf0c7b70919c656c96f824eb659ed2

Comment 2 Miroslav Suchý 2011-01-21 12:46:59 UTC
And it is already fixed in rhel6

Comment 3 Miroslav Suchý 2011-03-15 13:54:53 UTC
Cherry picked as rev. 201754.

Comment 6 Milan Zázrivec 2011-05-13 07:05:35 UTC
*** Bug 704297 has been marked as a duplicate of this bug. ***

Comment 7 Eliska Slobodova 2011-06-29 11:55:40 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
After a failed login into RHN, the rhn_register utility still showed a busy cursor. This happened even after pressing "Ok" or "Back" to acknowledge the error message. Now, a normal arrow cursor appears.

Comment 8 Eliska Slobodova 2011-06-29 12:02:41 UTC
    Technical note updated. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    Diffed Contents:
@@ -1 +1 @@
-After a failed login into RHN, the rhn_register utility still showed a busy cursor. This happened even after pressing "Ok" or "Back" to acknowledge the error message. Now, a normal arrow cursor appears.+Previously, when changing a channel subscription, the rhn-channel program accepted a username and a password only as parameters on the command line. As a consequence, other people could have read personal data. Now, users are prompted for the username and the password if they are not entered as parameters.

Comment 9 errata-xmlrpc 2011-07-21 07:08:10 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2011-0997.html