Uploaded image for project: 'Geode'
  1. Geode
  2. GEODE-2119

gfsh user and password visible in clear text

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.0.0-incubating
    • 1.1.0
    • gfsh
    • None

    Description

      Both gfsh connect and gfsh start server allow the specification on the command line of a user name and a password for use as credentials in authentication. Clear text versions of the user name and password are then visible
      1. if the user runs gfsh history
      2. in historyfile, if the user runs gfsh history --file=historyfile
      3. in the output of ps

      It would be worth a check to see if clear text versions of the user or password end up in any locator or server logs. I don't believe it does for gfsh connect, but it might for the start server case.

      Attachments

        Issue Links

          There are no Sub-Tasks for this issue.

          Activity

            People

              kduling Kevin Duling
              karensmolermiller Karen Smoler Miller
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: