storing password as plain text is not secure

Bug #977524 reported by Pavol Klačanský
4
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Landscape Client
Invalid
Undecided
Unassigned

Bug Description

Hi, after browsing gsettings with dconf-editor I have found that my password is stored as plaintext.
I would prefer store it in keyring (I have encrypted home, it is more cleaner to use keyring)

Thanks

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Just a note: this is what we call the "account password", and only controls access to computer registration *requests*. It's not the administrator's login password.

If your landscape account (not login: the *account*, like company name) is set to require a password (see "account settings"), then computers will only be able to *request* registrations if they use this password.

With or without a password, all computer registration requests become pending computers and need explicit administrator approval in order to be accepted. There is no automatic registration except for the LDS case, which is a different thing.

If you have an account password and the requesting computer didn't supply it, then it won't even become a pending computer. If the password was supplied correctly, or if there is no password for the account, then the requesting computer will become a pending computer also.

Revision history for this message
Pavol Klačanský (pavolzetor-deactivatedaccount) wrote :

Thanks for clarification, please, update GUI :), it was not clear at all for me :/

I just test it, I am translator so I have tested it with translations and was curious about this :)

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

It probably worked for you because when the account in landscape.canonical.com has no password, then any password on the client will work.

Thanks for the input, this is indeed a bit confusing.

Revision history for this message
🤖 Landscape Builder (landscape-builder) wrote :

This bug has not seen any activity in the last 6 months, so it is being automatically closed.

If you are still experiencing this issue, please feel free to re-open.

Landscape Team

Changed in landscape-client:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.