Bug 49515 - store demo user password in ucsschool config dir
store demo user password in ucsschool config dir
Status: CLOSED FIXED
Product: UCS@school
Classification: Unclassified
Component: General
UCS@school 4.4
Other Linux
: P5 normal (vote)
: UCS@school 4.4 v2-errata
Assigned To: Daniel Tröder
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-05-21 08:48 CEST by Daniel Tröder
Modified: 2019-07-26 13:58 CEST (History)
2 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 2: Improvement: Would be a product improvement
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 1: Nuisance – not a big deal but noticeable
User Pain: 0.023
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Cleanup
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Tröder univentionstaff 2019-05-21 08:48:33 CEST
When a demo school and demo users are created, the users passwords are currently stored in /etc/demoschool.secret.
A directory /etc/ucsschool exists however, and the password file should be created there (to keep /etc cleaner).
Comment 1 Daniel Tröder univentionstaff 2019-05-21 08:55:11 CEST
* The password file is now created as /etc/ucsschool/demoschool.secret.
  (Password file creation is now also safer.)
* The manual and quickstart guide have been adapted.
* Upon package update old files are moved to the new position, so that it matches the updated documentation.

Code is in branch dtroeder/49515_demo_password_config_dir (branched from 4.4).

[dtroeder/49515_demo_password_config_dir 958ef16fb] Bug #49515: store demo user password in ucsschool config dir

QA: Please reopen when it should be merged and built.
Comment 2 Daniel Tröder univentionstaff 2019-07-16 09:52:50 CEST
[4.4] e03baaf7c Bug #49515: store demo user password in ucsschool config dir
[4.4] 5c4c6b40b Bug #49515: improve password security, run update code only on update
[4.4] fb8778fd8 Bug #49515: changelog
[4.4] 3f1a5b3bb Bug #49515: advisory

ucs-school-metapackage (12.0.2-3)
Comment 3 Ole Schwiegert univentionstaff 2019-07-17 10:03:03 CEST
Changelog&Advisory: OK
Package installs: OK
secret file correct on new install: OK
"" on update: OK
Comment 4 Ole Schwiegert univentionstaff 2019-07-17 10:03:27 CEST
Manual adapted: OK
Placeholder link texts adapted: OK
Comment 5 Jürn Brodersen univentionstaff 2019-07-26 13:58:00 CEST
4.4 v3 released