cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: "Visser,Ramon R.D." <r.visser AT fontys.nl>
- To: Stefan Winter <stefan.winter AT restena.lu>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Cc: "Rademaker,Hans J.G." <h.rademaker AT fontys.nl>
- Subject: [[cat-users]] security fix clear text password in linux script eduroam
- Date: Mon, 18 Dec 2017 13:22:08 +0000
- Accept-language: nl-NL, en-US
Hello Stefan,
A colleague of me has made an suggestion for an more secure Linux configuration in case the first option based with python script fails.
I tried to translate his explanation: in case the first method fails the tools starts a second procedure with shell scripting. With this method the password is stored in plaintext in the wpa_supplicant config file. Users are informed about this during the installation.
Following my colleague there is an standard tool included in the wpa_supplicant suite which can hash the password in the component "wpa_passphrase". This has been added in rules 407 en 420 of the attachment.
Can this be helpful for the developers?
Met vriendelijke groet,
Ramon
|
Attachment:
eduroam-linux-Fontys_Hogescholen.sh
Description: eduroam-linux-Fontys_Hogescholen.sh
- [[cat-users]] security fix clear text password in linux script eduroam, Visser,Ramon R.D., 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Tomasz Wolniewicz, 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Alan Buxey, 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Rademaker,Hans J.G., 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Rademaker,Hans J.G., 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Alan Buxey, 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/19/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Tomasz Wolniewicz, 12/18/2017
- Re: [[cat-users]] security fix clear text password in linux script eduroam, Stefan Winter, 12/18/2017
Archive powered by MHonArc 2.6.19.