Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

[8.980][BUG] Problem with Gateway Shared Secret Field for ACC/SUM Connection

$
0
0
This is the bug that will not die :) It was supposed to be fixed some time ago... found it alive and well in 8.305 still, and in this beta...

I reported this a while back, and a few times back in other betas... latest report was here:
http://www.astaro.org/other-astaro-p...tml#post193570

Basically, if you have a Gateway Shared Secret defined on the UTM for the ACC connection that has an Ampersand '&' in it, Webadmin saves it with the html tag for & when you hit apply in the Central Management screen in the section where the password is defined. To reproduce:

1) Establish a connection between the UTM and ACC / SUM -- use an authentication secret that contains a & in it ... such as "test&secret"
2) Simply clone your current ACC definition (I slightly change the name to differentiate them) under Network Definitions on the UTM.
3) Go to the Central Management Screen, and DnD the cloned definition into the Gateway box, and hit apply (don't touch the authentication secret field).

Your connection to the ACC will fail, and you will see a login error (invalid password) in the ACC agent logs and down in the little monitoring window on the Central Management Screen. If you do a print configuration, you'll see that the password "test&secret" is now "test&secret" -- also confirmable by digging in via CC from the console.

I imagine this also affects the similar screen on the new SUM system where the shared secret is defined... but on the UTM is where it is a serious pain...

Update:
LOL Even simpler --- Skip step 2 and 3 above, and just hit Apply in the Central Management screen, and the password will be modified as described. BTW, tested this on Firefox 13.01, but if memory serves, this issue also occurs in IE9.

Viewing all articles
Browse latest Browse all 14361

Trending Articles