<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>5675</bug_id>
          
          <creation_ts>2013-12-17 07:35:31 +0000</creation_ts>
          <short_desc>Document adding a ROOT_PASSWD feature for images</short_desc>
          <delta_ts>2021-09-17 01:30:46 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>3.4 M4</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Laszlo Papp">lpapp</reporter>
          <assigned_to name="Michael Opdenacker">michael.opdenacker</assigned_to>
          <cc>bevenson</cc>
    
    <cc>bluelightning</cc>
    
    <cc>maciej.pijanowski</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>Qi.Chen</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>richard.purdie</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Yes (doc changes required)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>39442</commentid>
    <comment_count>0</comment_count>
    <who name="Laszlo Papp">lpapp</who>
    <bug_when>2013-12-17 07:35:31 +0000</bug_when>
    <thetext>Currently, one needs to use &quot;usermod -p ...&quot; with EXTRA_USERS_PARAMS, but this is a bit raw. Since, it is a common operation for images that the root password is not left blank by default, I would propose a dedicated feature, and hence variable for this as mentioned in the summary.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39998</commentid>
    <comment_count>1</comment_count>
    <who name="Bevenson">bevenson</who>
    <bug_when>2014-01-22 14:48:20 +0000</bug_when>
    <thetext>If I remember correctly, &quot;usermod -p&quot; expects a DES encrypted password which is limited to 8 characters.  For users that want to use a longer root password, I think we&apos;d want a different mechanism for setting the password.  Maybe have ROOT_PASSWD accept a string like &quot;encryption_type:cleartext_password&quot; that can be used for calling passwd or chpasswd?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>40065</commentid>
    <comment_count>2</comment_count>
    <who name="Laszlo Papp">lpapp</who>
    <bug_when>2014-01-28 16:50:13 +0000</bug_when>
    <thetext>I would prefer ROOT_PASSWORD_type like syntax instead for such features. I like avoiding &quot;raw strings&quot; as much as possible, and would prefer put the qualifier into the variable.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>40104</commentid>
    <comment_count>3</comment_count>
    <who name="Bevenson">bevenson</who>
    <bug_when>2014-01-30 13:43:22 +0000</bug_when>
    <thetext>Using a ROOT_PASSWD_type syntax does make more sense.  I propose the following:

1. ROOT_PASSWD_des uses DES encryption.  This will then be limited to 8 character passwords.  The user will be able to put in a password longer than 8 characters, but the system will truncate it to the first 8 characters and post a QA warning that the password was truncated.
2. ROOT_PASSWD defaults to ROOT_PASSWD_des.
3. ROOT_PASSWD_md5 used MD5 encryption.
4. ROOT_PASSWD declarations expects a plaintext password.  It is expected that the ROOT_PASSWD declaration will occur in an image recipe, which for a custom system belongs in a user&apos;s private layer.  This means the root password can be kept safe from those who are not expected to know the root password.
5. If multiple ROOT_PASSWD declarations exits, only the last one is used.  For example, if an image recipe contains:
  ROOT_PASSWD_des = &quot;password&quot;
  ROOT_PASSWD_md5 = &quot;second_password&quot;
then the system would set the root password to &quot;second_password&quot; and encrypt it using the MD5 algorithm.  We may want a QA warning if multiple ROOT_PASSWD declarations are found so the user knows that the root password may not be what they expect.
6. ROOT_PASSWD cannot be appended.  For example:
  ROOT_PASSWD = &quot;pass&quot;
  ROOT_PASSWD += &quot;word&quot;
results in an error.
7. Add the ROOT_PASSWD variable to the Yocto Project manual and a few examples of usage.

I&apos;m not sure if other encryption methods would be necessary.  Busybox supports only DES and MD5, but I know other password managers support SHA256 and SHA512.  It would depend on what demand people had for more options.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>40124</commentid>
    <comment_count>4</comment_count>
    <who name="Laszlo Papp">lpapp</who>
    <bug_when>2014-01-31 00:50:11 +0000</bug_when>
    <thetext>Yes, that is more or less inline with what I thought, too. Although, I would make it possible to load the root password from file, e.g. ROOT_PASSWD_file = /path/to/my/password/file.

The question is: would anyone be willing to implement it any soon?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>76006</commentid>
    <comment_count>5</comment_count>
    <who name="Maciej Pijanowski">maciej.pijanowski</who>
    <bug_when>2017-08-19 10:57:53 +0000</bug_when>
    <thetext>Hello
I&apos;m looking for some unassigned bugs to try start contributing and this looks reasonably to do. Do you think above feature description is up to date? Any hints where this should be implemented (new bbclass, existing class, somewhere else?).
Regards</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>84502</commentid>
    <comment_count>6</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2019-07-25 15:13:09 +0000</bug_when>
    <thetext>I believe its possible to do this already using image post processing commands, we should document those better and give an example of doing this. The details will vary case to case which is why no one default will work in general.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91464</commentid>
    <comment_count>7</comment_count>
    <who name="Chen Qi">Qi.Chen</who>
    <bug_when>2021-09-17 01:30:46 +0000</bug_when>
    <thetext>This could be achieved by using extrausers. There&apos;s no need to use another ROOT_PASSWD feature. Besides, as the clear password support has been removed from oe-core, the ROOT_PASSWD is also not appropriate any more.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>