SSL keys for iTalc in Edubuntu only gets generated at build time
Bug #714864 reported by
Jonathan Carter
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
italc (Ubuntu) |
Fix Released
|
High
|
Stéphane Graber | ||
Karmic |
Fix Released
|
High
|
Kees Cook | ||
Lucid |
Fix Released
|
High
|
Kees Cook | ||
Maverick |
Fix Released
|
High
|
Stéphane Graber | ||
Natty |
Fix Released
|
High
|
Stéphane Graber |
Bug Description
The private keys for iTalc on Edubuntu gets generated when the live image is build from iTalc's postinst.
The problem is that keys aren't generated again after that in ubiquity's target-config or anywhere else, which results in every single Edubuntu machine of the same release having the same keys, which results in every Edubuntu machine being remotely controllable by anyone with iTalc or a VNC client installed.
This affects all Edubuntu live DVD's that ship with iTalc.
Stéphane is busy working on SRU's, and debdiffs will be available shortly.
Changed in italc (Ubuntu Maverick): | |
status: | New → Incomplete |
Changed in italc (Ubuntu Lucid): | |
status: | New → Fix Committed |
Changed in italc (Ubuntu Karmic): | |
status: | New → Fix Committed |
assignee: | nobody → Kees Cook (kees) |
Changed in italc (Ubuntu Lucid): | |
assignee: | nobody → Kees Cook (kees) |
Changed in italc (Ubuntu Maverick): | |
assignee: | nobody → Stéphane Graber (stgraber) |
importance: | Undecided → High |
Changed in italc (Ubuntu Lucid): | |
importance: | Undecided → High |
Changed in italc (Ubuntu Karmic): | |
importance: | Undecided → High |
Changed in italc (Ubuntu Natty): | |
milestone: | none → natty-alpha-3 |
Changed in italc (Ubuntu Maverick): | |
status: | Incomplete → Fix Committed |
visibility: | private → public |
Changed in italc (Ubuntu Natty): | |
importance: | Critical → High |
tags: | added: patch |
Changed in italc (Ubuntu Natty): | |
status: | Confirmed → Triaged |
To post a comment you must log in.
root@orilla: /data/iso# for squash in *.squashfs italc/keys/ */*/key d752b55604abe3f 26 tmp/etc/ italc/keys/ private/ admin/key 40b2391d66ab560 e6 tmp/etc/ italc/keys/ private/ supporter/ key 5c0d35a13acc7f2 f4 tmp/etc/ italc/keys/ private/ teacher/ key db4c69bb5a0b2ea c1 tmp/etc/ italc/keys/ public/ admin/key 132db8c2973b4b9 fb tmp/etc/ italc/keys/ public/ supporter/ key b2df334da081227 97 tmp/etc/ italc/keys/ public/ teacher/ key f894317b5ec5305 2d tmp/etc/ italc/keys/ private/ admin/key aeaa50f2e7a8c3e 72 tmp/etc/ italc/keys/ private/ supporter/ key 795c24898483da1 2a tmp/etc/ italc/keys/ private/ teacher/ key e96eb970e6ab173 c9 tmp/etc/ italc/keys/ public/ admin/key 5a5f475fcf04b65 43 tmp/etc/ italc/keys/ public/ supporter/ key 4f5e4edb36ab0e8 bf tmp/etc/ italc/keys/ public/ teacher/ key 1912bd24a2c0df0 77 tmp/etc/ italc/keys/ private/ admin/key 545a91798b3e402 a4 tmp/etc/ italc/keys/ private/ supporter/ key a1591887c11f878 8c tmp/etc/ italc/keys/ private/ teacher/ key 6be69c750097fb8 2a tmp/etc/ italc/keys/ public/ admin/key 3c28d411a5ee450 91 tmp/etc/ italc/keys/ public/ supporter/ key 28de52572099e2c 0b tmp/etc/ italc/keys/ public/ teacher/ key 2b186cf8830c44c 2b tmp/etc/ italc/keys/ private/ admin/key 0c0e60b6369fdb1 73 tmp/etc/ italc/keys/ private/ supporter/ key b258e32a7c957e8 fe tmp/etc/ italc/keys/ private/ teacher/ key a2d962ec368b681 f6 tmp/etc/ italc/keys/ public/ admin/key 6e017bcfc86b28b 9f tmp/etc/ italc/keys/ public/ supporter/ key db71329f47f041c 94 tmp/etc/ italc/keys/ public/ teacher/ key 3a26c70fe488147 02 tmp/etc/ italc/keys/ private/ admin/key e681bbba693a184 be tmp/etc/ italc/keys/ private/ supporter/ key 592eced24a5175b 90 tmp/etc/ italc/keys/ private/ teacher/ key d6da6d2bb125e8f 68 tmp/etc/ italc/keys/ public/ admin/key 9211207784e410a e1 tmp/etc/ italc/keys/ public/ supporter/ key 652e67fc9f5d17d ea tmp/etc/ italc/keys/ public/ teacher/ key 3c94e7b7ed36092 cb tmp/etc/ italc/keys/ private/ admin/key e8b4524ff6c3b73 56 tmp/etc/ italc/keys/ private/ supporter/ key d71c50b0cbe219d ce tmp/etc/ italc/keys/ private/ teacher/ key d515ae427e9d244 c5 tmp/etc/ italc/keys/ public/ admin/key 493a7276b12e08e e0 tmp/etc/ italc/keys/ public/ supporter/ key 61fea94b8f57abc c4 tmp/etc/ italc/keys/ public/ teacher/ key
> do
> mount -o loop $squash tmp/
> md5sum tmp/etc/
> umount tmp
> done
38437fd93f2728e
701806e8744e155
ce39df180047019
122c1a9f324c997
783d858340ed89c
2a6cdd46ec7d52e
cab58fba8b1e002
f04bc4de36ca6c3
ae3a07a17da0dbd
b11f5dbbbc6392c
ed6f414a92f558a
4415ebbe044d900
9746f2ac0e55c76
9224a0b6a09cd29
5adfa4044d68a8f
43c88a01ea36f05
544d88f8ce8c8de
adbf57dd4419f3a
c0244cda824f75b
bd1576d3824dc33
1953dffb20ef8f0
5021b1e3c8ce147
8f372d3a35763db
bdd706777034072
909b6771f03df33
1fa2f1f8709dff5
12cb0152c344df5
554991d4382fa98
933c823eeaeba39
d81ee1636da323c
443e7a853ac6e96
0a0745860a4d055
143a0371bd3ea11
d53811801490e7d
29d2e819b9fbcbe
89e52ef5a045952
That's for all the known values of the keys we want to remove