[Bug 206669] New: VNC Remote Access via X11: spaces in password don't work but no hint given by YaST
https://bugzilla.novell.com/show_bug.cgi?id=206669 Summary: VNC Remote Access via X11: spaces in password don't work but no hint given by YaST Product: SUSE Linux 10.1 Version: Final Platform: i686 OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: YaST2 AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: danielstefanmader@web.de QAContact: jsrain@novell.com The VNC display sharing with the sax2 YaST Control Center option works nice unless the specified password doesn't contain spaces or colons. Though this might be a restriction of X.org the user should be given a warning that the password will not work since it is invalid. mada@Santenay:~> rpm -qa | grep xorg xorg-x11-devel-6.9.0-48 xorg-x11-driver-video-6.9.0-46.15 xorg-x11-fonts-scalable-6.9.0-48 xorg-x11-Xvnc-6.9.0-48 xorg-x11-fonts-75dpi-6.9.0-48 xorg-x11-fonts-100dpi-6.9.0-48 xorg-x11-server-glx-6.9.0-50.17 xorg-x11-server-6.9.0-50.20 xorg-x11-6.9.0-50.17 xorg-x11-driver-video-nvidia-6.9.0-46.15 xorg-x11-libs-6.9.0-50.17 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 aj@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|bnc-team- |sndirsch@novell.com |screening@forge.provo.novell| |.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 sndirsch@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|sndirsch@novell.com |bnc-team-screening@forge.provo.novell.com Severity|Normal |Minor ------- Comment #1 from sndirsch@novell.com 2006-09-20 12:50 MST ------- Yes, AFAIK it is a restriction in Xvnc. So this needs to be detected in YaST2. IMHO this is a minor issue. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 cthiel@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |snwint@novell.com AssignedTo|bnc-team- |yast2-maintainers@suse.de |screening@forge.provo.novell| |.com | ------- Comment #2 from cthiel@novell.com 2006-09-20 15:05 MST ------- I guess this doesn't only need to get fixed in YaST, but in linuxrc as well. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 fehr@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|yast2-maintainers@suse.de |snwint@novell.com ------- Comment #3 from fehr@novell.com 2006-09-21 01:51 MST ------- Reassigned to maintainer of linuxrc -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 snwint@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|snwint@novell.com |ms@novell.com ------- Comment #4 from snwint@novell.com 2006-09-21 03:33 MST ------- Xvnc not supporting spaces in passwords sounds like grotesque nonsense to me. More likely I'd suspect a quoting issue in one of the shell scripts used to setup vnc. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 ms@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|ms@novell.com |max@novell.com ------- Comment #5 from ms@novell.com 2006-09-21 06:03 MST ------- Hmm, I don't think so. The startup script does the following: $VNCPASS /root/.vnc/passwd "$VNCPassword" The variable $VNCPassword is an exported variable from the linuxrc environment and is never touched in the scripts. The contents are directly passed to the program $VNCPASS = /usr/bin/vncpasswd.arg So I assume a problem with the space handling in the vncpasswd.arg which is part of the tightvnc package. Assigning to maintainer of tightvnc By the way setting spaces in a password is a bad idea at all -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 ------- Comment #6 from max@novell.com 2006-09-21 09:24 MST ------- I think you guys are all running into the wrong direction. As I understand Daniel, the problem didn't happen on a VNC installation, but in an installed system, when during the X configuration he checked the box to export the local display via VNC. So linuxrc the installation system are certainly out of the loop here. I also tested vncpasswd.arg with passwords containing spaces, and didn't see any problems with it. So, my guess is, that the password gets truncated at the first space by YaST or SAX when it is queried from the user before it gets written to the disk. BTW, what's wrong with spaces in passwords? It's a regular character that shouldn't cause any problems. The only characters I would discourage people from using in passwords are umlauts, because they might be hit by encoding problems. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 ------- Comment #7 from danielstefanmader@web.de 2006-09-21 09:35 MST ------- @ c0mment #6: Yes, this is exactly what I mean... I was already looking up information about linuxrc and couldn't come up with a reason for why it should be related to the problem but blaimed my average Linux user skills for not understanding... And yes, I use spaces and other chars extensively in other (regular) passwords since I think it makes things much more secure :) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=206669 ms@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED ------- Comment #9 from ms@novell.com 2006-09-22 03:43 MST ------- aha, we are talking about the installed system ;) ok first of all the initial report is correct. A space in the password string confuses sax2 because the shell which is invocing the createVNC.sh script is called like this: /usr/share/sax/libsax/createVNC.sh 123 123 so only the first portion of the passowrd is used. Additionally this is a security problem because you can pass a shell quoted command as password which is executed. Both issues have been fixed -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com