Bug 692916 - 0.8.997-8.git20110331.fc15 still saves VPN password
Summary: 0.8.997-8.git20110331.fc15 still saves VPN password
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: NetworkManager
Version: 15
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Dan Williams
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 494832
TreeView+ depends on / blocked
 
Reported: 2011-04-01 16:35 UTC by Paul W. Frields
Modified: 2011-07-29 20:57 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-07-29 20:57:37 UTC
Type: ---


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 691618 0 unspecified CLOSED OTP is saved for subsequent connection attempts 2021-02-22 00:41:40 UTC
Red Hat Bugzilla 711174 0 unspecified CLOSED NM openvpn remembers password even though I tell it not to 2021-02-22 00:41:40 UTC

Internal Links: 691618 711174

Description Paul W. Frields 2011-04-01 16:35:14 UTC
Using NM-openvpn (0.8.995-1).  I am using a Password type VPN with two-factor authentication, one being a timed component.  In the profile there is no option to store/not store the password.  When I activate the VPN, the password is stored in the connection profile without my knowledge.  When I try to activate it again, no dialog is presented.  The old password is used and fails.  To discontinue this behavior, I have to edit the profile and manually delete the password each time I want to reconnect.

Comment 1 Michal Schmidt 2011-04-02 12:16:23 UTC
I am seeing the same behaviour.
Storing VPN passwords without the user's consent is a security risk.

Comment 2 Dan Williams 2011-04-05 17:14:53 UTC
This is a combination problem between the import procedure for your existing connections (nm-applet) and a lack of coping with new features in NM on NetworkManager-openvpn's part.  That has now been fixed upstream and the pieces will dribble into Fedora.  It'll take a small fix on your part though since it's an error in the import process, which for you has already happened.  More details when the update comes through...

Comment 3 tom.jenkinson 2011-05-27 05:40:22 UTC
I see this too, and I didn't "import my existing connections" I worked from a fresh install of F15

Comment 4 Vinny Valdez 2011-06-29 17:56:27 UTC
I see this same problem, clean install of Fedora 15, no import used. I have to edit the connection and clear my previous password out in order to be prompted again. Is there a temporary work-around I can implement to clear this out without manually editing the connection?

Comment 5 Mark Wielaard 2011-07-29 07:20:49 UTC
(In reply to comment #2)
> This is a combination problem between the import procedure for your existing
> connections (nm-applet) and a lack of coping with new features in NM on
> NetworkManager-openvpn's part.  That has now been fixed upstream and the pieces
> will dribble into Fedora.

Is there a pointer to the upstream fix?

>  It'll take a small fix on your part though since
> it's an error in the import process, which for you has already happened.  More
> details when the update comes through...

Any updates on the details? I tried to erase my old VPN connection and
enter the information by hand instead of importing from a file. But that
didn't help.

Comment 6 Vinny Valdez 2011-07-29 14:37:36 UTC
I found Bug 691618 Comment 3 that details a successful work-around as long as the connection details are not edited with the UI after the manual change.

Comment 7 Mark Wielaard 2011-07-29 16:58:00 UTC
(In reply to comment #6)
> I found Bug 691618 Comment 3 that details a successful work-around as long as
> the connection details are not edited with the UI after the manual change.

Thanks. Editing /etc/NetworkManager/system-connections/<name> and setting password-flags=3 in the [vpn] section worked! Finally the password isn't
saved anymore.


Note You need to log in before you can comment on or make changes to this bug.