Bug 21227 - Vom VNC Passwort im UVMM werden nur 8 Stellen ausgewertet
Vom VNC Passwort im UVMM werden nur 8 Stellen ausgewertet
Status: CLOSED WONTFIX
Product: UCS
Classification: Unclassified
Component: Virtualization - UVMM
UCS 2.4
Other Linux
: P4 normal (vote)
: UCS 3.x
Assigned To: UCS maintainers
:
Depends on:
Blocks: 48106
  Show dependency treegraph
 
Reported: 2011-01-18 10:47 CET by Tobias Scherer
Modified: 2023-06-28 10:46 CEST (History)
3 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Scherer univentionstaff 2011-01-18 10:47:32 CET
Berichtet an Ticket#: 2011011710013502

Im UVMM Modul der UMC kann für den Direktzugriff per VNC ein Passwort vergeben werden. Hier werden allerdings nur die ersten 8 Stellen ausgewertet. Wird ein längeres Passwort angegeben, reichen im VNC Viewer die ersten 8 Stellen zur Authentisierung aus.
Comment 1 Philipp Hahn univentionstaff 2014-06-24 18:18:33 CEST
Quoting qemu-kvm/qemu-doc.texi:
> The VNC protocol has limited support for password based authentication. Since
> the protocol limits passwords to 8 characters it should not be considered to
> provide high security. The password can be fairly easily brute-forced by a
> client making repeat connections. For this reason, a VNC server using
> password authentication should be restricted to only listen on the loopback
> interface or UNIX domain sockets.

QEMU supports authentication through SASL, which probably supports longer passwords, but not all VNC viewers support that extension, especially noVNC does not.
Comment 2 Stefan Gohmann univentionstaff 2016-04-25 07:52:17 CEST
This issue has been filed against UCS 2.4.

UCS 2.4 is out of maintenance and many UCS components have vastly changed in
later releases. Thus, this issue is now being closed.

If this issue still occurs in newer UCS versions, please use "Clone this bug".
In this case please provide detailed information on how this issue is affecting
you.