TrackStudio login cookies

Discuss problems installing or using TrackStudio.

TrackStudio login cookies

Postby victor » Wed Oct 29, 2003 9:27 pm

Hello,

Trying the 'remember me' checkbox I have seen that the trackstudio cookie show the user password raw, this is: without encription... this is a hard security lack I think...

Thanks,

PD: Can I install the new 2.8 release in my production server and do the transdata?
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Re: TrackStudio login cookies

Postby admin » Wed Oct 29, 2003 10:59 pm

victor wrote:Hello,
Trying the 'remember me' checkbox I have seen that the trackstudio cookie show the user password raw, this is: without encription... this is a hard security lack I think...


Yes, we need unencrypted password to authenticate via LDAP, we can't give password hash to the LDAP server. Of course, we can implement some two-way encryptions, but it has so much sense - current solution less comfortable, but fair.

victor wrote:PD: Can I install the new 2.8 release in my production server and do the transdata?

I suggest you following before install on production server (we use similar procedure for TrackStudio Host):
1) Backup your database
2) Restore it to different database (You use MSSQL ? It should not be complex task).
3) Upgrade you new database
4) Substitute gr_user.user_email with your or empty e-mail.
5) Try it on your real data for a day or two.
6) If all goes OK for you - upgrade live database.

Another reason for such upgrade procedure - I am a little distracted at the moment, as I have a new 3 day old son (my first child) and can't fix bugs fast, especially until next week.
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Re: TrackStudio login cookies

Postby victor » Wed Oct 29, 2003 11:02 pm

admin wrote:Yes, we need unencrypted password to authenticate via LDAP, we can't give password hash to the LDAP server. Of course, we can implement some two-way encryptions, but it has so much sense - current solution less comfortable, but fair.


I dont understand 'but...'?
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Re: TrackStudio login cookies

Postby admin » Wed Oct 29, 2003 11:04 pm

victor wrote:
admin wrote:Yes, we need unencrypted password to authenticate via LDAP, we can't give password hash to the LDAP server. Of course, we can implement some two-way encryptions, but it has so much sense - current solution less comfortable, but fair.


I dont understand 'but...'?


Sorry, "but current solution is fair".
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Re: TrackStudio login cookies

Postby victor » Wed Oct 29, 2003 11:05 pm

admin wrote:Another reason for such upgrade procedure - I am a little distracted at the moment, as I have a new 3 day old son (my first child) and can't fix bugs fast, especially until next week.


Ops! I didn't read your message completely before my first reply... CONGRATULATIONS! :)
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Re: TrackStudio login cookies

Postby admin » Wed Oct 29, 2003 11:09 pm

victor wrote:
admin wrote:Another reason for such upgrade procedure - I am a little distracted at the moment, as I have a new 3 day old son (my first child) and can't fix bugs fast, especially until next week.


Ops! I didn't read your message completely before my first reply... CONGRATULATIONS! :)

Thank you :-)
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Re: TrackStudio login cookies

Postby victor » Wed Oct 29, 2003 11:10 pm

admin wrote:
victor wrote:
admin wrote:Another reason for such upgrade procedure - I am a little distracted at the moment, as I have a new 3 day old son (my first child) and can't fix bugs fast, especially until next week.


Ops! I didn't read your message completely before my first reply... CONGRATULATIONS! :)

Thank you :-)


Photographs? ;)
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Re: TrackStudio login cookies

Postby admin » Wed Oct 29, 2003 11:13 pm

victor wrote:
admin wrote:
victor wrote:
admin wrote:Another reason for such upgrade procedure - I am a little distracted at the moment, as I have a new 3 day old son (my first child) and can't fix bugs fast, especially until next week.


Ops! I didn't read your message completely before my first reply... CONGRATULATIONS! :)

Thank you :-)


Photographs? ;)


I have yet, but I hope...
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Re: TrackStudio login cookies

Postby greg » Thu Oct 30, 2003 12:32 am

admin wrote: I am a little distracted at the moment, as I have a new 3 day old son (my first child)


Congratulations! :-D
greg
 
Posts: 18
Joined: Thu Jun 12, 2003 11:04 pm
Location: Idaho, USA

Re: TrackStudio login cookies

Postby greg » Thu Oct 30, 2003 12:39 am

admin wrote:Yes, we need unencrypted password to authenticate via LDAP, we can't give password hash to the LDAP server. Of course, we can implement some two-way encryptions, but it has so much sense - current solution less comfortable, but fair.

Perhaps this can be the first development project for your new son. ;-)
greg
 
Posts: 18
Joined: Thu Jun 12, 2003 11:04 pm
Location: Idaho, USA

Next

Return to TrackStudio Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron