php5-mcrypt problem

Bug #121381 reported by Patrick Hetu
8
Affects Status Importance Assigned to Milestone
ldap-account-manager
Unknown
Unknown
ldap-account-manager (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

ldap-account-manager 1.3.0-1 produces warning after the update of php5-mcrypt package to the version 5.1.2-1ubuntu1:
"""
PHP Warning: mcrypt_decrypt() [function.mcrypt-decrypt]: The IV parameter must be as long as the blocksize in /usr/share/ldap-account-manager/lib/ldap.inc on line 378
"""

php5 version: 5.2.3-1ubuntu1

Revision history for this message
Patrick Hetu (patrick-hetu) wrote :
Revision history for this message
p3net (admin-p3net) wrote :

This does indeed appear to be a problem, and I too can confirm it's existence. Set as confirmed.

Changed in ldap-account-manager:
status: Unconfirmed → Confirmed
William Grant (wgrant)
Changed in ldap-account-manager:
importance: Undecided → Medium
Daniel Hahler (blueyed)
description: updated
Revision history for this message
Loye Young (loyeyoung) wrote :

Same here.

I've done a little bit of poking around in the *.inc files. The error seems to have something to do with the $iv variable in the client-side cookie.

I note that I am also running phpmyadmin and phpldapadmin, and neither of them are having the problem. In both cases, cookie authentication using mcrypt is explicitly configured, but I can't find anyplace in ldap-account-manager that configures the authentication regime.

Loye Young
Laredo, Texas

Revision history for this message
Daniel Hahler (blueyed) wrote :

I've reported the bug upstream:
https://sourceforge.net/tracker/?func=detail&atid=537211&aid=1742543&group_id=73243

There's a question waiting for feedback:
"""
Did the error disappear after you log in to LAM again?
This problem usually happens if MCrypt is activated while you are
currently using LAM.
"""

Because I have not experienced the problem myself (I'm not using ldap-account-manager), please provide feedback there to fix this issue.

Revision history for this message
Roland Gruber (mail-rolandgruber) wrote :

There was no feedback to my questions and the upstream bug report
already expired.

I suggest to close this bug.

Best regards

Roland Gruber

Changed in ldap-account-manager (Ubuntu):
status: Confirmed → Invalid
Revision history for this message
Daniel Hahler (blueyed) wrote :

Closing as "Fix released", according to upstream bug report (where it is considered to be fixed in the VCS)

Changed in ldap-account-manager (Ubuntu):
status: Invalid → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.