Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-15830

Avoid master's password stored as clear text

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Not a Bug
    • Icon: Major Major
    • fuse-7.9-GA
    • fuse-7.8-GA
    • Karaf
    • False
    • False
    • 2021-M3
    • 0
    • 0% 0%
    • Todo
    • Undefined

      When using the jasypt-encryption bundle to encrypt sensible configuration values for Blueprint files (i.e. LDAP module user's password), you have to store the master's password in clear text form inside an environment variable or Karaf system property. It would be good to have a way to hide the master's password using the same mechanism used for credential store, where it is masked inside a Karaf system property (security by obscurity).

              ggrzybek Grzegorz Grzybek
              rhn-support-fvaleri Federico Valeri
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: