Bug 360041

Summary: Wallet password change ignored by KRDC.
Product: [Applications] krdc Reporter: Tralen <tunairaiol>
Component: RDPAssignee: Urs Wolfer <uwolfer>
Status: RESOLVED WAITINGFORINFO    
Severity: major    
Priority: NOR    
Version First Reported In: unspecified   
Target Milestone: ---   
Platform: Arch Linux   
OS: Linux   
Latest Commit: Version Fixed/Implemented In:
Sentry Crash Report:

Description Tralen 2016-03-03 19:27:32 UTC
Using KRDC 4.14.16 on Manjaro.

Any connection that I set to store the password with kwallet ignores if I change the password for the wallet. Other application detect that the wallet had its password changed, but not KRDC.

The wallet is then in an inconsistent state, because the other applications are able to connect to it with the new password while KRDC is only able to connect to it with the old password.

Deleting the wallet does not help either, nor does creating a new wallet. KRDC always asks for the same default wallet and ignores any change to it.

This is a security bug. The passwords have been changed following security procedures, but a user with the old password can still log in through KRDC. The solution for now is to disable the wallet for each connection.

Reproducible: Always

Steps to Reproduce:
1. Create a RDP connection set to store the password in a wallet.
2. Login normally and quit. 
3. Change the wallet password.
4. Reopen KRDC and try to login in with the new password.


Actual Results:  
KRDC will only accept the old password, even though it was changed. This will persist even after rebooting or killing the wallet daemon and relaunching it.

Expected Results:  
KRDC should pick up the new password and require it instead.

I'm running Manjaro 15.12 update 2016-02-29.
Comment 1 Justin Zobel 2021-03-11 01:23:49 UTC
Thank you for the bug report.

As this report hasn't seen any changes in 5 years or more, we ask if you can please confirm that the issue still persists.

If this bug is no longer persisting or relevant please change the status to resolved.
Comment 2 Tralen 2021-03-11 12:43:31 UTC
I no longer use KDE, so I can't confirm. Closing the issue.