Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-15830

Avoid master's password stored as clear text

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Not a Bug
    • Icon: Major Major
    • fuse-7.9-GA
    • fuse-7.8-GA
    • Karaf
    • None
    • False
    • False
    • 2021-M3
    • % %
    • ?
    • Undefined

      When using the jasypt-encryption bundle to encrypt sensible configuration values for Blueprint files (i.e. LDAP module user's password), you have to store the master's password in clear text form inside an environment variable or Karaf system property. It would be good to have a way to hide the master's password using the same mechanism used for credential store, where it is masked inside a Karaf system property (security by obscurity).

            ggrzybek Grzegorz Grzybek
            rhn-support-fvaleri Federico Valeri
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: