Bug 360041 - Wallet password change ignored by KRDC.
Summary: Wallet password change ignored by KRDC.
Status: RESOLVED WAITINGFORINFO
Alias: None
Product: krdc
Classification: Applications
Component: RDP (other bugs)
Version First Reported In: unspecified
Platform: Arch Linux Linux
: NOR major
Target Milestone: ---
Assignee: Urs Wolfer
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-03-03 19:27 UTC by Tralen
Modified: 2021-03-11 12:45 UTC (History)
0 users

See Also:
Latest Commit:
Version Fixed/Implemented In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tralen 2016-03-03 19:27:32 UTC
Using KRDC 4.14.16 on Manjaro.

Any connection that I set to store the password with kwallet ignores if I change the password for the wallet. Other application detect that the wallet had its password changed, but not KRDC.

The wallet is then in an inconsistent state, because the other applications are able to connect to it with the new password while KRDC is only able to connect to it with the old password.

Deleting the wallet does not help either, nor does creating a new wallet. KRDC always asks for the same default wallet and ignores any change to it.

This is a security bug. The passwords have been changed following security procedures, but a user with the old password can still log in through KRDC. The solution for now is to disable the wallet for each connection.

Reproducible: Always

Steps to Reproduce:
1. Create a RDP connection set to store the password in a wallet.
2. Login normally and quit. 
3. Change the wallet password.
4. Reopen KRDC and try to login in with the new password.


Actual Results:  
KRDC will only accept the old password, even though it was changed. This will persist even after rebooting or killing the wallet daemon and relaunching it.

Expected Results:  
KRDC should pick up the new password and require it instead.

I'm running Manjaro 15.12 update 2016-02-29.
Comment 1 Justin Zobel 2021-03-11 01:23:49 UTC
Thank you for the bug report.

As this report hasn't seen any changes in 5 years or more, we ask if you can please confirm that the issue still persists.

If this bug is no longer persisting or relevant please change the status to resolved.
Comment 2 Tralen 2021-03-11 12:43:31 UTC
I no longer use KDE, so I can't confirm. Closing the issue.