JBoss ON decrypts rhq-server.properties file database password during installation
Issue
- Installation process removes obfuscation of password.
- Passwords decryption during startup
- at start-time rhq.server.database.password is transformed into plain text
- while it is starting the password is now in the clear in the properties file
Environment
- Red Hat JBoss Operations Network (ON) 3.1.2
RHQ_SERVER_HOME/bin/rhq-server.properites
includes:rhq.autoinstall.enabled=true
- Obfuscated value for
rhq.server.database.password
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.