Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

[CPANEL-21776] Mask passphrase when using cPanel to import SSH keys

Discussion in 'Security' started by Willfosho, Jul 14, 2018.

Tags:
  1. Willfosho

    Willfosho Registered

    Joined:
    Jun 18, 2018
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Sydney
    cPanel Access Level:
    DataCenter Provider
    Hi Guys,

    I'd consider this a bug in the new Git feature in cPanel72, but i guess it depends on your perspective! I guess you could also call it a feature?

    When importing keys for a repo, the passpharse field is a text field instead of a password field. This isn't overly annoying in itself, unless you're super paranoid people are looking over your shoulder. However Chrome, and most other browsers, will try to be helpful and pre-fill that passphrase in the future. It's a bit of a security concern for any shared machines.

    Is there a reason it wasn't set as a password field, or has it just been overlooked? This isn't the case when importing root ssh keys, for example.
     
  2. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    45,531
    Likes Received:
    1,965
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello @Willfosho,

    I've opened internal case CPANEL-21776 to report that characters entered in the "Passphrase" field in "cPanel >> SSH Access >> Manage SSH Keys >> Import Key" are not masked, as this is contrary to the behavior observed "WHM >> Manage root's SSH Keys”. I'll monitor this case and update this thread with more information as it becomes available.

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    45,531
    Likes Received:
    1,965
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello @Willfosho,

    Internal case CPANEL-21776 was accepted. "Passphrase" is tentatively set to become a password field in "cPanel >> SSH Access >> Manage SSH Keys >> Import Key" as of cPanel & WHM version 76.

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    scristopher likes this.
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice