Bug 373632

Summary: YaST should not echo password for WPA-EAP configuration
Product: [openSUSE] openSUSE 10.3 Reporter: Brian Merrell <bgmerrell>
Component: YaST2Assignee: Michal Zugec <mzugec>
Status: RESOLVED FIXED QA Contact: Jiri Srain <jsrain>
Severity: Normal    
Priority: P5 - None Keywords: security
Version: Final   
Target Milestone: ---   
Hardware: All   
OS: openSUSE 10.3   
Whiteboard:
Found By: Integration Test Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Brian Merrell 2008-03-25 15:04:38 UTC
PROBLEM STATEMENT:

In both yast and yast2, the password is echoed as it is being typed when configuring a wireless card to use WPA-EAP.

REPRO: 

1.  Run yast or yast2 as root (in a machine with a wireless card)
2.  Select "Network Card" under "Network Devices"
3.  Click/highlight a wireless card and select "Configure"
4.  Select "Next" at the "Network Card Setup" screen
5.  At the "Wireless Network Card Configuration" screen, enter any ESSID and select WPA-EAP as the "Authentication Mode."  Then click "Next."
6.  Type a potential password in the "Password" field.

RESULTS:  

The password is echoed to the screen.

EXPECTED RESULTS:  

The password should not be echoed the screen.  Asterisks should replace each character in yast, and dots should replace each character in yast2.  This is how other passwords are handled.

COMMENTS:

I filed this under the Yast2 component, is there a reason there isn't a generic YaST component for both ncurses yast and yast2?
Comment 1 Michal Zugec 2008-04-02 20:25:06 UTC
fixed in yast2-network-2.16.32