[Bug 271220] New: Accountwizard accesses api.opendesktop.org by default

Andre Heinecke aheinecke at intevation.de
Mon Apr 18 15:44:12 BST 2011


https://bugs.kde.org/show_bug.cgi?id=271220

           Summary: Accountwizard accesses api.opendesktop.org by default
           Product: kdepim
           Version: GIT (master)
          Platform: Compiled Sources
        OS/Version: All
            Status: NEW
          Severity: normal
          Priority: NOR
         Component: wizards
        AssignedTo: kdepim-bugs at kde.org
        ReportedBy: aheinecke at intevation.de


Version:           GIT (master) (using Devel) 
OS:                All

When you open the accountwizard it accesses api.opendesktop.org before you do
anything.
This is observable when you do not have a valid certificate for
api.opendesktop.org installed it will bring up the Server Authentication
dialog.

This is even with Enterprise build options where "Find provider settings on the
Internet" is disabled by default. 

This is a security problem.

Reproducible: Always

Steps to Reproduce:
Do not have any valid certificate for api.opendesktop.org.
Open the accountwizard.


Expected Results:  
The accountwizard should not connect to anything apart from the server you
configure if you do not explicitly tell it to.

-- 
Configure bugmail: https://bugs.kde.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the Kdepim-bugs mailing list