-
Feature Request
-
Resolution: Done
-
Critical
-
2.2, 2.3, 1.2
-
False
-
-
False
The database password in the file "/etc/tower/conf.d/postgresy.py" is stored in plain text. So is pulp.py
This makes the system vulnerable.
Customers need a provision to encrypt the password rather than having it in plain text. Or we find a way to protect the file contents.
Current workaround isĀ https://access.redhat.com/solutions/4344381, but it's not supported