Project

General

Profile

Bug #33339

Limit IPMI admin password to 20 characters

Added by Bill O'Hanlon about 1 year ago. Updated 8 months ago.

Status:
Done
Priority:
No priority
Assignee:
Dennis Mullen
Category:
GUI (new)
Target version:
Seen in:
Severity:
Low
Reason for Closing:
Reason for Blocked:
Needs QA:
No
Needs Doc:
No
Needs Merging:
No
Needs Automation:
No
Support Suite Ticket:
n/a
Hardware Configuration:
ChangeLog Required:
No

Description

A better description is that the GUI takes a longer password than 20 characters for IPMI, and seems to set it successfully, but I can't log in with that long password.

It's possible that the GUI was truncating the PW, but since it's dots and the box is full, it's hard to see that it's just blocking additional characters.

Recovering the IPMI was painful.


Related issues

Related to FreeNAS - Bug #48867: Limit IPMI admin password to 20 characters in legacy UIDone
Related to FreeNAS - Bug #49585: Limit IPMI admin password to 20 characters in middlewareDone

History

#1 Updated by Bill O'Hanlon about 1 year ago

Bill O'Hanlon wrote:

A better description is that the GUI takes a longer password than 20 characters for IPMI, and seems to set it successfully, but I can't log in with that long password.

It's possible that the GUI was truncating the PW, but since it's displayed as dots and the box is full, it's hard to see if it's just blocking additional characters.

Recovering the IPMI was painful.

#2 Updated by Eric Loewenthal about 1 year ago

I vaguely remember the ASpeed 2400 on my X10SLM+-F only working with passwords up to 19 characters. Cannot confirm the value, nor did I ever find documentation about that. And that was in the IPMI webGUI, which clearly doesn't validate this, either.

If nobody knows of an IPMI spec that defines this, I'd recommend adding a warning to the GUI and to the manual. If needed, we can catalog experimental results on different motherboards on the forum.

#3 Updated by Joshua Sirrine about 1 year ago

I could have sworn we went around with this problem before. While the issue isn't fixed (and there may be good reasons for this that I don't know), at the time the general concensus was that the WebGUI was doing something nasty(TM) with long passwords or certain characters and needed to be worked out or have the WebGUI not allow those characters to be used.

IIRC the customer that first had this problem resolved the issue by logging into the IPMI controller directly and setting the password instead of using the TrueNAS WebGUI. So that may be a hint.

This knowledge is several years old, so it may be wrong, etc. I'd use this info as a starting point for identifying the issue, but I'd definitely validate what I've written here. ;)

#4 Avatar?id=13649&size=24x24 Updated by Ben Gadd about 1 year ago

Investigate what are our (iX) password limitations and/or requirements

Note to Dev: Followup with Bill about this ticket

#5 Updated by Dru Lavigne about 1 year ago

  • Assignee changed from Release Council to Erin Clark
  • Target version changed from Backlog to 11.3

Erin: please have the UI throw an error when the user hits the allowed char limit. Bill has some suggestions on what that char limit should be (as it varies by BMC).

#6 Updated by Erin Clark 12 months ago

  • Status changed from Unscreened to Screened

#7 Updated by Erin Clark 12 months ago

  • Status changed from Screened to Not Started

#8 Updated by Dru Lavigne 10 months ago

  • Subject changed from Current GUI allows long (>20) character password to be set on IPMI admin user to Limit IPMI admin password to 20 characters
  • Target version changed from 11.3 to 11.2-RC1

#10 Updated by Erin Clark 9 months ago

  • Assignee changed from Erin Clark to Vaibhav Chauhan

#11 Updated by Dennis Mullen 8 months ago

  • Assignee changed from Vaibhav Chauhan to Dennis Mullen

#12 Updated by Dennis Mullen 8 months ago

  • Status changed from Not Started to In Progress

#14 Updated by Lola Yang 8 months ago

  • Status changed from In Progress to Ready for Testing
  • Needs Merging changed from Yes to No

#15 Updated by Jeff Ervin 8 months ago

31968

Test Passed FreeNAS-11.2-MASTER-201809260853

#16 Updated by Aaron St. John 8 months ago

  • Needs Doc changed from Yes to No

#17 Updated by Dru Lavigne 8 months ago

  • Needs Merging changed from No to Yes

#18 Updated by Dru Lavigne 8 months ago

  • Related to Bug #48867: Limit IPMI admin password to 20 characters in legacy UI added

#19 Updated by Dru Lavigne 8 months ago

  • Status changed from Passed Testing to Done
  • Needs Merging changed from Yes to No

#20 Updated by Dru Lavigne 7 months ago

  • Related to Bug #49585: Limit IPMI admin password to 20 characters in middleware added

Also available in: Atom PDF