Debian Bug report logs - #604081
Does not show password mismatch when first entered root password is empty

version graph

Package: user-setup; Maintainer for user-setup is Debian Install System Team <[email protected]>; Source for user-setup is src:user-setup (PTS, buildd, popcon).

Reported by: Daniel Pocock <[email protected]>

Date: Sat, 20 Nov 2010 00:27:04 UTC

Severity: normal

Tags: confirmed

Found in versions user-setup/1.55, user-setup/1.48

Full log


Message #21 received at [email protected] (full text, mbox, reply):

Received: (at 604081) by bugs.debian.org; 2 Mar 2014 14:46:29 +0000
From [email protected] Sun Mar 02 14:46:29 2014
X-Spam-Checker-Version: SpamAssassin 3.3.2-bugs.debian.org_2005_01_02
	(2011-06-06) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-14.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
	HAS_BUG_NUMBER,PGPSIGNATURE autolearn=ham
	version=3.3.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 8; hammy, 151; neutral, 59; spammy, 0.
	spammytokens: hammytokens:0.000-+--H*o:Debian, 0.000-+--H*F:U*kibi,
	0.000-+--H*rp:U*kibi, 0.000-+--H*RU:sk:glenfid, 0.000-+--H*r:sk:glenfid
Return-path: <[email protected]>
Received: from glenfiddich.mraw.org ([62.210.215.98])
	by buxtehude.debian.org with esmtps (TLS1.2:DHE_RSA_AES_128_CBC_SHA1:128)
	(Exim 4.80)
	(envelope-from <[email protected]>)
	id 1WK7et-0001eT-3X
	for [email protected]; Sun, 02 Mar 2014 14:46:29 +0000
Received: from localhost ([::1] helo=mraw.org)
	by glenfiddich.mraw.org with esmtp (Exim 4.80)
	(envelope-from <[email protected]>)
	id 1WK7eq-00048r-Kx; Sun, 02 Mar 2014 15:46:24 +0100
Date: Sun, 2 Mar 2014 15:46:24 +0100
From: Cyril Brulebois <[email protected]>
To: Christian PERRIER <[email protected]>, [email protected]
Cc: Daniel Pocock <[email protected]>
Subject: Re: Bug#604081: root password mismatch
Message-ID: <[email protected]>
References: <[email protected]>
 <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="6TrnltStXW4iwmi0"
Content-Disposition: inline
In-Reply-To: <[email protected]>
Organization: Debian
User-Agent: Mutt/1.5.21 (2010-09-15)
[Message part 1 (text/plain, inline)]
Control: found -1 1.48
Control: found -1 1.55
Control: tag -1 confirmed

Christian PERRIER <[email protected]> (2010-11-20):
> reassign 604081 user-setup
> retitle 604081 Does not show password mismatch when first entered root password is empty
> thanks
> 
> Quoting Daniel Pocock ([email protected]):
> > Package: installation-reports
> > 
> > Installing amd64 as a domU in xen
> > 
> > At the first prompt for root password, just hit enter
> > 
> > At the second prompt, type a password
> > 
> > No password-mismatch error is displayed, installer proceeds to
> > setting up a user account
> > 
> > Once rebooted, root login impossible using blank password or the
> > `repeat' password
> > 
> > Mount the root fs (e.g. from dom0 or another OS), inspect /etc/shadow:
> > 
> > root:!:14932:0:99999:7:::
> 
> When the root password is empty, root account is disabled. This is
> what the first template says.
> 
> Still, one can understand that entering the pwd empty, then setting
> something in the confirmation is user error and the user should have a
> chance to correct it. And we should anyway to give the false
> impression that a root password will be set.
> 
> Reassigning to user-setup as this bug belongs to that package.

Still the case in wheezy and above, so recording the versions
accordingly.

Mraw,
KiBi.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


Debian bug tracking system administrator <[email protected]>. Last modified: Tue May 13 17:59:24 2025; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.