From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 1988 invoked from network); 20 Dec 2001 22:48:18 -0000 Received: from unknown (HELO fencepost.gnu.org) (199.232.76.164) by sources.redhat.com with SMTP; 20 Dec 2001 22:48:18 -0000 Received: from localhost ([127.0.0.1] helo=fencepost.gnu.org) by fencepost.gnu.org with esmtp (Exim 3.22 #1 (Debian)) id 16HByx-00038t-00; Thu, 20 Dec 2001 17:48:07 -0500 Received: from gnats by fencepost.gnu.org with local (Exim 3.22 #1 (Debian)) id 16HBwt-0002vR-00; Thu, 20 Dec 2001 17:45:59 -0500 From: elzubeir@fakkir.net To: pdm-gnats@zamazal.org,gnats-prs@gnu.org,bug-gnats@gnu.org Reply-To: elzubeir@fakkir.net Subject: gnats/314: gnats.host_acess access-level overrides gnatsd.access settings Message-Id: Sender: gnats-prs-admin@gnu.org Errors-To: gnats-prs-admin@gnu.org X-BeenThere: gnats-prs@gnu.org X-Mailman-Version: 2.0.5 Precedence: bulk List-Help: List-Post: List-Subscribe: , List-Id: Copies of bug tracking system messages List-Archive: Date: Mon, 22 Oct 2001 08:09:00 -0000 X-SW-Source: 2001-q4/txt/msg00086.txt.bz2 >Number: 314 >Category: gnats >Synopsis: gnats.host_acess access-level overrides gnatsd.access settings >Confidential: no >Severity: serious >Priority: high >Responsible: unassigned >State: open >Class: sw-bug >Submitter-Id: net >Arrival-Date: Thu Dec 20 17:45:58 -0500 2001 >Originator: Mohammed Elzueir >Release: 4.0-alpha >Organization: Arabeyes Project (http://www.arabeyes.org/) >Environment: Debian Linux (woody), i386. >Description: When the gnatsd.host_access access-level is set to 'view' (for example), and gnatsd.acess has users with various access-levels - only the access-level set on gnatsd.host_access prevail. That does not appear to happen when the passwords are stored in clear-text (ie. $0$passme). If the passwords are encrypted, it fails to see the user access-level and defaults to gnatsd.host_acess settings. >How-To-Repeat: 1. In /etc/gnats/gnatsd.host_access put: 127.0.0.1:view: 2. In /var/lib/gnats/gnats-db/gnats-adm/gnatsd.access put: plainguy:$0$test:edit:default cryptguy:4/1d3Y7NqgISI:admin:default The cryptguy password is 'test'. 'plainguy' will have proper access-level, whereas 'cryptguy' will default to 'view'. >Fix: Unknown >Unformatted: _______________________________________________ Gnats-prs mailing list Gnats-prs@gnu.org http://mail.gnu.org/mailman/listinfo/gnats-prs