https://bugs.kde.org/show_bug.cgi?id=451641

Murz <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #4 from Murz <[email protected]> ---
Leaving this RESOLVED; just adding context for anyone who finds this bug later.

This is still reproducible on current Ubuntu 26.04 + Plasma 6 / plasma-nm when
configuring a GlobalProtect (gp) OpenConnect VPN with:

- Allow Cisco Secure Desktop trojan = yes
- CSD Wrapper Script = /usr/libexec/openconnect/hipreport.sh

plasma-nm correctly stores the settings in the NM connection
(enable_csd_trojan=yes, csd_wrapper=...). The functional ignore happens in
NetworkManager-openconnect itself: it intentionally never passes --csd-wrapper
to openconnect (if (FALSE && priv->tun_name) in nm-openconnect-service.c, since
2019). Result: the GP gateway asks for a HIP report, openconnect warns that
connectivity may be limited, and HIP-gated TCP access stays blocked.

So comment 3’s “3rd-party UI tweaking tool” close reason does not match this
report — the UI here is stock plasma-nm OpenConnect/GlobalProtect settings. The
remaining KDE-side UX issue is that Connections still offers CSD / HIP fields
that NM-openconnect silently ignores, with no user-visible error.

Upstream ticket filed against NetworkManager-openconnect (with links to this
bug and Fedora #1777087):
https://gitlab.gnome.org/GNOME/NetworkManager-openconnect/-/work_items/154

Possible Plasma follow-up (separate from reopening this as a functional bug):
hide/disable the CSD controls or show a warning that HIP/CSD is currently
unsupported via NetworkManager-openconnect.

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to