ecryptfs keyring not cleared on logout

Bug #576582 reported by Tony Yarusso
262
This bug affects 2 people
Affects Status Importance Assigned to Milestone
ecryptfs-utils (Ubuntu)
Confirmed
High
Unassigned
Jaunty
Confirmed
High
Unassigned
Karmic
Confirmed
High
Unassigned
Lucid
Confirmed
High
Unassigned

Bug Description

Binary package hint: ecryptfs-utils

Running Ubuntu 10.04, installed from final release, Alternate CD, i386.
ecryptfs-utils:
  Installed: 83-0ubuntu3
libecryptfs0:
  Installed: 83-0ubuntu3

I installed using the encrypted /home option (all of /home, not just ~/Private). I have noticed that the @u keyring is not properly cleared when I log out, allowed root to access my files unencrypted through 'su' between when I log out and the next reboot. An IRC log from #ecryptfs on OFTC with the full details is attached.

Revision history for this message
Tony Yarusso (tonyyarusso) wrote :
visibility: private → public
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I can reproduce this with lucid. The keyring isn't being cleared when the user logs out.

Changed in ecryptfs-utils (Ubuntu):
status: New → Confirmed
importance: Undecided → High
Changed in ecryptfs-utils (Ubuntu Lucid):
status: New → Confirmed
importance: Undecided → High
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I can reproduce this with jaunty and karmic also.

Changed in ecryptfs-utils (Ubuntu Karmic):
status: New → Confirmed
Changed in ecryptfs-utils (Ubuntu Jaunty):
status: New → Confirmed
Changed in ecryptfs-utils (Ubuntu Jaunty):
importance: Undecided → High
Changed in ecryptfs-utils (Ubuntu Karmic):
importance: Undecided → High
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.