Bug 11136 - drakx-net does not configure WPA Enterprise connections correctly.
Summary: drakx-net does not configure WPA Enterprise connections correctly.
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 4
Hardware: All Linux
Priority: High major
Target Milestone: Mageia 4
Assignee: Thierry Vignaud
QA Contact:
URL:
Whiteboard:
Keywords: NEEDINFO, PATCH, Triaged
: 10866 (view as bug list)
Depends on:
Blocks:
 
Reported: 2013-09-03 01:00 CEST by Patrick Hibbs
Modified: 2015-11-20 22:20 CET (History)
2 users (show)

See Also:
Source RPM: drakx-net-1.24-1.mga3.src.rpm
CVE:
Status comment:


Attachments
Fixes the shown private key password in mcc and fixes the strings issue. (948 bytes, patch)
2013-09-03 01:01 CEST, Patrick Hibbs
Details | Diff

Description Patrick Hibbs 2013-09-03 01:00:06 CEST
Description of problem:
When using mcc to configure WPA Enterprise connections the following occurs:

1. If a user enters a private key password it is shown on screen.

This is inconvenient, as a unprivileged user could see the password as it's being typed in or copied. Considering that mcc hides the other passwords, it may as well hide this one. (Consistancy.)

2. If a user configures the following: Private key, Private key password, or a CA cert they are not saved as strings in /etc/wpa_supplicant.conf.

This means that the connection will not come up as wpa_supplicant will not parse the private key password, or the paths correctly, and will not load them as a result. 

I'm attaching a patch that fixes the above.

Version-Release number of selected component (if applicable):
1.24-1.mga3

How reproducible:
Always.

Steps to Reproduce:
1. Open mcc
2. Try to configure a WPA Enterprise network.
3. Watch the connection not come up. (And the password be exposed.)


Reproducible: 

Steps to Reproduce:
Comment 1 Patrick Hibbs 2013-09-03 01:01:25 CEST
Created attachment 4314 [details]
Fixes the shown private key password in mcc and fixes the strings issue.

Patch.
Manuel Hiebel 2013-09-07 00:02:49 CEST

Keywords: (none) => PATCH, Triaged
Assignee: bugsquad => mageia

Comment 2 Thierry Vignaud 2015-02-11 09:28:44 CET
mga3 is no more supported

CC: (none) => thierry.vignaud
Version: 3 => Cauldron

David Walser 2015-03-03 00:07:11 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=10866

Comment 3 Zombie Ryushu 2015-03-03 03:07:04 CET
This Patch is still an issue in Mageia 4. Re-assigning.

Priority: Normal => High
Status: NEW => REOPENED
CC: (none) => zombie_ryushu
Version: Cauldron => 4
Target Milestone: --- => Mageia 4
Severity: normal => major

Comment 4 Thierry Vignaud 2015-03-11 16:12:31 CET
I fear altering those parameters might break other wifi modes.
Has it been tested with no WPA Enterprise wifi?

Keywords: (none) => NEEDINFO

Comment 5 Mageia Robot 2015-03-11 21:21:24 CET
commit 26e679b7ca6db25739237a4c718d4f05f39d14c2
Author: Thierry Vignaud <thierry.vignaud@...>
Date:   Wed Mar 11 21:19:21 2015 +0100

    hide EAP client private key password (mga#11136)
---
 Commit Link:
   http://gitweb.mageia.org/software/drakx-net/commit/?id=26e679b7ca6db25739237a4c718d4f05f39d14c2
Comment 6 Mageia Robot 2015-03-11 21:30:17 CET
commit 2a2bfde64a237f6a4ab4aa52bb1ee40bc4586ba5
Author: Thierry Vignaud <thierry.vignaud@...>
Date:   Wed Mar 11 21:26:44 2015 +0100

    fix not saving WPA Enterprise settings (mga#11136)
    
    Private key, Private key password & CA cert were no saved in
    /etc/wpa_supplicant.conf if provided (Patrick Hibbs)
---
 Commit Link:
   http://gitweb.mageia.org/software/drakx-net/commit/?id=2a2bfde64a237f6a4ab4aa52bb1ee40bc4586ba5
Comment 7 Thierry Vignaud 2015-03-11 21:31:43 CET
Fixed (tested by Patrick Hibbs & Evan Vittitow).
Sorry for the delay for applying your patch which looks safe.

Status: REOPENED => RESOLVED
Resolution: (none) => FIXED

Comment 8 Thierry Vignaud 2015-03-11 21:32:02 CET
Though I'll need to backport them to mga4 branch

Status: RESOLVED => REOPENED
Resolution: FIXED => (none)

Comment 9 Thierry Vignaud 2015-03-18 14:08:33 CET
BTW did you tested current cauldron?
Comment 10 Thierry Vignaud 2015-06-05 15:00:22 CEST
Closing

Status: REOPENED => RESOLVED
Resolution: (none) => FIXED
Assignee: mageia => thierry.vignaud

Comment 11 Marja Van Waes 2015-11-20 22:20:23 CET
*** Bug 10866 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.