Package: freedombox
Version: 26.11.1~bpo13+1
Severity: normal

Dear Maintainer,

I'm installed freedombox in a systemd container. Networking is managed by 
systemd.network
with NetworkManager configured to ignore all the interfaces. I needed to 
install btrfs-progs.

I was then able to access the https://cass.6site0/freedombox URL and paste in 
my secret.
I entered an account called owner and gave it a password. I performed an 
upgrade.

I then tried to add some SSH keys and add a user. I received
some failure messages from the plinth logs.

Sep 01 18:18:13 cass freedombox[171]: » ssh..set_keys("owner", "", "owner", 
****) 
Sep 01 18:18:13 cass freedombox[171]: Error running action 
ssh..set_keys("owner", "", "owner", ****): Permissi
onError("Invalid credentials")
                                      Action traceback:
                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/actions.py", line 501, i
n _privileged_call
                                      ╞     return_values = 
func(*arguments['args'], **arguments['kwargs'])
                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.p
y", line 98, in set_keys
                                      ╞     _validate_user(auth_user, 
auth_password, must_be_admin=must_be_adm
in)
                                      ╞     
~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
^^^
                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in 
_validate_user
                                      ╞     raise PermissionError('Invalid 
credentials')
Sep 01 18:18:14 cass freedombox[171]: GET /sys/users/owner/edit/

I may have incorrectly entered the owner password in that one, but later

Sep 01 18:18:14 cass freedombox[171]: GET /sys/users/owner/edit/

Sep 01 18:18:14 cass freedombox[171]: » ssh..get_keys("owner")

Sep 01 18:18:14 cass freedombox[171]: » users..get_group_users("admin")

Sep 01 18:20:25 cass freedombox[171]: POST /sys/users/owner/edit/

Sep 01 18:20:25 cass freedombox[171]: » ssh..get_keys("owner")

Sep 01 18:20:25 cass freedombox[171]: » users..get_group_users("admin")

Sep 01 18:20:25 cass freedombox[171]: » users..get_user_groups("owner")

Sep 01 18:20:25 cass freedombox[171]: » ssh..set_keys("owner", "ssh-ed25519 
AAAAC3NzaC1lZDI1NTE5AAAAIJY8q6TDObPW524Vna/2UT6PBgV05nD5n77D+mbyVAnW 
weaves-elliptic", "owner", ****)

Sep 01 18:20:25 cass freedombox[171]: Error running action 
ssh..set_keys("owner", "ssh-ed25519 
AAAAC3NzaC1lZDI1NTE5AAAAIJY8q6TDObPW524Vna/2UT6PBgV05nD5n77D+mbyVAnW 
weaves-elliptic", "owner", ****): PermissionError("Invalid credentials")

                                      Action traceback:

                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/actions.py", line 501, in 
_privileged_call

                                      ╞     return_values = 
func(*arguments['args'], **arguments['kwargs'])

                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 98, in 
set_keys

                                      ╞     _validate_user(auth_user, 
auth_password, must_be_admin=must_be_admin)

                                      ╞     
~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

                                      ╞   File 
"/usr/lib/python3/dist-packages/plinth/modules/ssh/privileged.py", line 32, in 
_validate_user

                                      ╞     raise PermissionError('Invalid 
credentials')

Sep 01 18:20:25 cass freedombox[171]: GET /sys/users/owner/edit/


In that one,  I may have gotten further. I did manage to get the notification 
that the Authorization Password 
worked, but something else failed.

I suspected that the LDAP password wasn't working because most of the error 
were invalid credentials after an
LDAP operation.

I went out to the OS command line and tried to change the password of the only 
account in LDAP the owner
account. And the LDAP password I entered during the LDAP/nslcd installation 
didn't work.

The /etc/nslcd.conf file looks incomplete: 

# The DN to bind with for normal lookups.
#binddn cn=annonymous,dc=example,dc=net
#bindpw secret
 
# The DN used for password modifications by root.
#rootpwmoddn cn=admin,dc=example,dc=com

Despite trying to create two users - neither appeared on the file system.

So I think it is a broken distribution. There's something wrong with the 
linkage between plinth and 
the LDAP.


-- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.107+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_USER
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages freedombox depends on:
ii  apache2                       2.4.68-1~deb13u1
ii  augeas-tools                  1.14.1-1.1~deb13u1
ii  avahi-daemon                  0.8-16
ii  avahi-utils                   0.8-16
ii  batctl                        2025.0-2
ii  bind9-dnsutils                1:9.20.26-1~deb13u1
ii  borgbackup                    1.4.0-5
ii  certbot                       4.0.0-2+deb13u1
ii  cockpit                       337-1+deb13u2
ii  curl                          8.14.1-2+deb13u4
ii  debconf                       1.5.91
ii  debsecan                      0.4.20.1
ii  fail2ban                      1.1.0-8
ii  firewalld                     2.3.1-1+deb13u1
ii  fuse3                         3.17.2-3
ii  gdisk                         1.0.10-2
ii  gettext                       0.23.1-2
ii  gir1.2-glib-2.0               2.84.4-3~deb13u3
ii  gir1.2-nm-1.0                 1.52.1-1
ii  gir1.2-udisks-2.0             2.10.1-12.1+deb13u2
ii  gpg                           2.4.7-21+deb13u1+b4
ii  iproute2                      6.15.0-1
ii  javascript-common             12+nmu1
ii  ldap-utils                    2.6.10+dfsg-1
ii  ldapscripts                   2.0.8-2
ii  libapache2-mod-auth-openidc   2.4.17-1
ii  libglib2.0-bin                2.84.4-3~deb13u3
ii  libjs-bootstrap5              5.3.5+dfsg-4
ii  libjs-htmx                    2.0.4-1
ii  libnss-ldapd                  0.9.13-1
ii  libpam-ldapd                  0.9.13-1
ii  lsof                          4.99.4+dfsg-2
ii  needrestart                   3.11-1
ii  netcat-openbsd                1.229-1
ii  network-manager               1.52.1-1
ii  nftables                      1.1.3-1
ii  node-popper2                  2.11.2-8
ii  nslcd                         0.9.13-1
ii  openssh-server                1:10.0p1-7+deb13u4
ii  openssl                       3.5.7-1~deb13u2
ii  parted                        3.6-5
ii  php-fpm                       2:8.4+96
ii  php8.4-fpm [php-fpm]          8.4.24-1~deb13u1
ii  popularity-contest            1.78
ii  ppp                           2.5.2-1+1
ii  pppoe                         4.0-1
ii  python3                       3.13.5-1
ii  python3-apt                   3.0.0
ii  python3-argon2                21.1.0-3
ii  python3-augeas                1.2.0-1
ii  python3-bootstrapform         3.4-9
ii  python3-cherrypy3             18.10.0-1
ii  python3-configobj             5.0.9-1
ii  python3-dbus                  1.4.0-1
ii  python3-django                3:4.2.28-0+deb13u2
ii  python3-django-axes           5.39.0-6
ii  python3-django-bootstrapform  3.4-9
ii  python3-django-captcha        0.6.2-1
ii  python3-django-ipware         4.0.2-1
ii  python3-django-oauth-toolkit  3.0.1-1
ii  python3-django-stronghold     0.4.0+debian-2
ii  python3-fido2                 1.2.0-2
ii  python3-gi                    3.50.0-4+b1
ii  python3-markupsafe            2.1.5-1+b3
ii  python3-pampy                 2.0.2-3
ii  python3-pexpect               4.9-3
ii  python3-psutil                7.0.0-2
ii  python3-requests              2.32.3+dfsg-5+deb13u1
ii  python3-ruamel.yaml           0.18.10+ds-1
ii  python3-systemd               235-1+b6
ii  python3-yaml                  6.0.2-1+b2
ii  samba-common-bin              2:4.22.10+dfsg-0+deb13u2
ii  slapd                         2.6.10+dfsg-1
ii  snapper                       0.10.6-1.2
ii  sshfs                         3.7.3-1.2~deb13u1
ii  sshpass                       1.10-0.1
ii  ssl-cert                      1.1.3
ii  sudo                          1.9.16p2-3+deb13u2
ii  systemd [systemd-sysusers]    257.13-1~deb13u1
ii  systemd-timesyncd             257.13-1~deb13u1
ii  tdb-tools                     2:1.4.13+samba4.22.10+dfsg-0+deb13u2
ii  udisks2                       2.10.1-12.1+deb13u2
ii  unattended-upgrades           2.12
ii  wget                          1.25.0-2
ii  zram-tools                    0.3.7-1

Versions of packages freedombox recommends:
ii  e2fsprogs           1.47.2-3+b11
ii  firmware-ath9k-htc  1.4.0-110-ge888634+dfsg1-0.1
ii  freedombox-doc-en   26.11.1~bpo13+1
ii  freedombox-doc-es   26.11.1~bpo13+1
ii  libnss-mdns         0.15.1-4+b1
ii  libnss-myhostname   257.13-1~deb13u1
ii  locales             2.41-12+deb13u3
ii  locales-all         2.41-12+deb13u3
ii  openssh-client      1:10.0p1-7+deb13u4
ii  powermgmt-base      1.38
ii  psmisc              23.7-2

freedombox suggests no packages.

-- no debconf information

Reply via email to