Hello Eric, or anyone else affected,

Accepted unity-control-center into trusty-proposed. The package will
build now and be available at http://launchpad.net/ubuntu/+source/unity-
control-center/14.04.3+14.04.20140604-0ubuntu1 in a few hours, and then
in the -proposed repository.

Please help us by testing this new package.  See
https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to
enable and use -proposed.  Your feedback will aid us getting this update
out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug,
mentioning the version of the package you tested, and change the tag
from verification-needed to verification-done. If it does not fix the
bug for you, please add a comment stating that, and change the tag to
verification-failed.  In either case, details of your testing will help
us make a better decision.

Further information regarding the verification process can be found at
https://wiki.ubuntu.com/QATeam/PerformingSRUVerification .  Thank you in
advance!

** Changed in: unity-control-center (Ubuntu Trusty)
       Status: New => Fix Committed

** Tags added: verification-needed

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to unity-control-center in Ubuntu.
https://bugs.launchpad.net/bugs/1314886

Title:
  Changing user from no password login to disabled leaves user in no
  password login group

Status in “unity-control-center” package in Ubuntu:
  Fix Released
Status in “unity-control-center” source package in Trusty:
  Fix Committed

Bug description:
  * Impact
  disabling accounts which are set to "log in without password" leads to users 
still able to log in

  * Test case
  - use unity-control-center to configure an user password more to "log in 
without password"
  - change the mode to "desactivated"
  - try to log in with that user

  The user shouldn't be able to log in

  * Regression potential
  check that the different password modes work as they should

  --------

  If a user is set to login without a password and subsequently the
  account is disabled, the user is not removed from the nopassword login
  group. The result is that the user can still login even though the
  admin has disabled to account.

  This is a security issue and is present in 12.04, 13.10, and 14.04.

  This stems from the failure to reset to the password mode away from
  password_mode_none to password_mode_regular.

  I have submitted a merge proposal to fix this at
  https://code.launchpad.net/~echaskes/unity-control-center/fix-user-
  password-dialog

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unity-control-center/+bug/1314886/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to