WPA Enterprise password stored in plaintext

Bug #45005 reported by espenh
260
Affects Status Importance Assigned to Milestone
NetworkManager
Fix Released
Unknown
network-manager (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: network-manager

Stores wpa enterprise password in plain text in daemon.log and gconf-editor under system/networking/wireless

Revision history for this message
Martin Pitt (pitti) wrote :

Hi espenh,

thank you for your report! However, it is not really a secret, I have heard discussions about this in #ubuntu-devel, so I make this bug public.

Scott, the logging can certainly be solved easily, but I'm not sure about gconf. It's quite similar to ifupdown, which stores WEP passwords into /etc/network/interfaces.

Changed in network-manager:
status: Unconfirmed → Confirmed
Changed in network-manager:
status: Unknown → Unconfirmed
Revision history for this message
Scott Robinson (scott-ubuntu) wrote :

gnome-keyring is used for storing the passwords now.

wpa_supplicant no longer shows passwords in its logging output.

Changed in network-manager:
status: Confirmed → Fix Released
Changed in network-manager:
status: New → Confirmed
Changed in network-manager:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.