pam authentication is failing on CUPS CGI interface

Bug #7724 reported by Mark Shuttleworth
4
Affects Status Importance Assigned to Milestone
cupsys (Ubuntu)
Fix Released
Medium
Martin Pitt

Bug Description

On a clean ubuntu warty install, version cusys 1.1.20final+cvs20040330-4ubuntu7
fire up a browser and go to:

http://localhost:631/admin/

Enter your user name and password, it fails.

In /var/log/cups/error_log I see a message that pam authentication failed.

Desired outcome: some group that we trust, possibly local users or users with
sudo access, should be able to access the cups web admin pages.

Revision history for this message
Matt Zimmerman (mdz) wrote :

We are deprecating the CUPS web interface; it's ugly, insecure and we have
gnome-cups-manager. It should probably be disabled entirely to avoid confusion

Revision history for this message
Martin Pitt (pitti) wrote :

It is not easy to disable the web interface (or only the /admin parts of it); I
played around with various Allow/Deny combinations and AuthTypes, cups always
allows localhost access.

But even if that were possible, we should not do that since the cups libraries
(used by gnome-cups-manager) use the very same CGI interface to configure
printers. Disabling the web interface means to disable gnome-cups-manager, too.

Revision history for this message
Martin Pitt (pitti) wrote :

I've got no idea how to fix this (other than modifying the web pages to not link
to the admin section any more). See previous bug followup for the reasons.

So what shall we do about this? WONTFIX?

Revision history for this message
Mark Shuttleworth (sabdfl) wrote :

Please create a new bug to fix this in the existing CUPS pages then! And the
error page when access is denied should also explain why, and that this is not
an error.

Revision history for this message
Martin Pitt (pitti) wrote :

fixed in cupsys_1.1.20final+cvs20040330-4ubuntu10:

 cupsys (1.1.20final+cvs20040330-4ubuntu10) warty; urgency=low
 .
   * added patch 35nowebadmin to add a warning to the title bar that
     administrative tasks are disabled in the web interface for security
     reasons and point to GNOME CUPS manager; also updated the error page on
     failed admin logins (Warty bug #7724)
   * added patch ja-nowebadmin.ptch that is manually applied after uudecoding
     and unpacking ja.tar.gz.uu, to do the same for the Japanese pages
   * by now, there are only German and French translations of the warnings

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.