ssh-add -D (or -d) does not delete the keys

Bug #228340 reported by Igor Katson
256
Affects Status Importance Assigned to Milestone
Debian
New
Unknown
gnome-keyring (Ubuntu)
Invalid
Medium
Unassigned

Bug Description

Ubuntu Linux 2.6.24-16-rt, openssh-client version 1:4.7p1-8ubuntu1

I just can't delete the keys from the ssh-agent. It says that the operation has been successful, but they are still in there, and ssh-agent continues to ligon without any passphrase prompt. Here is the exact command sequence.

ssh-add -l
2048 xx:xx:xx:xx:xx..... (RSA)

ssh-add -D
All identities removed.

ssh-add -d
Identity removed: /home/descent/.ssh/id_rsa (/home/descent/.ssh/id_rsa.pub)

ssh-add -l
2048 xx:xx:xx:xx:xx..... (RSA)

Revision history for this message
Igor Katson (descentspb) wrote :

I marked it as a security vulnerability cause if i leave my terminal running, anyone can access the remote server, even gain the root access without entering any passwords.

Revision history for this message
Igor Katson (descentspb) wrote :

Made some search, and figured out that it's because of the gnome-keyring-manager. The same problem http://groups.google.com/group/linux.debian.bugs.dist/browse_thread/thread/150d601e274584e8/8982eb1a03d596ed

Lars Ljung (larslj)
Changed in gnome-keyring-manager:
status: New → Confirmed
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thanks for the bug report. This particular bug has already been reported, but feel free to report any other bugs you find.

Changed in gnome-keyring:
importance: Undecided → Medium
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.