Cannot login-without-password when home folder is encrypted

Bug #1318030 reported by Jeroen
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-control-center (Ubuntu)
New
Undecided
Unassigned

Bug Description

Users of whom the home folder is encrypted using the CLI (unfortunately there is no GUI option for this, see https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/1279766), and for which the 'login without password' is set, cannot login.

Steps to reproduce:
1. Using an Administrator account, create a new user in System Settings > User Accounts and set a password.
2. Open a shell and encrypt the newly created user folder by 'sudo ecryptfs-migrate-home -u <username>'
3. Login into the new account: successful
4. Logout and login into the Administrator account and select 'Login without password' for the newly created user.
5. Login into the new account: cannot login (the password field for this users now displays 'Log in' but trying to login results in a flickering screen and back to the login screen.

Ubuntu 14.04 x64 (reproducable on two different machines)

Jeroen (alpenblauwtje)
information type: Private Security → Public Security
Revision history for this message
Seth Arnold (seth-arnold) wrote :

This sounds like expected behaviour to me -- the login password is used to encrypt the filesystem key. Without a login password at login time, the files should be unavailable, and thus there's no home directory to contain anything of value for the user.

There might be a better way to tell the user that a password is required for encrypted home directories though.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Public Security → Public
Jeroen (alpenblauwtje)
summary: - Cannot login-without-password when home folder in encrypted
+ Cannot login-without-password when home folder is encrypted
description: updated
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.