It's all about the answers!

Ask a question

Password saved in clear text


Harel Fishgrund (2622) | asked Aug 31 '11, 5:22 a.m.
Hi there,
I looked into my .metdata/.log file and I found out that whenever I'm using scm command, the command is written to the log file while saving my password in clear text to it! :shock:
Is there a way to avoid this password saving or it least mask it?
Thanx in advance,
Harel

3 answers



permanent link
Michael Valenta (3.7k3) | answered Aug 31 '11, 10:17 a.m.
FORUM MODERATOR / JAZZ DEVELOPER
This is due to OSGi which our command line uses. Here's an RTC work item that tracks the issue;

https://jazz.net/jazz/web/projects/Rational%20Team%20Concert#action=com.ibm.team.workitem.viewWorkItem&id=158182

but the fix would need to come from OSGi. Here's the work item at that level:

https://bugs.eclipse.org/bugs/show_bug.cgi?id=341541

permanent link
Evan Hughes (2.4k1318) | answered Aug 31 '11, 10:18 a.m.
JAZZ DEVELOPER
Hi Harel,

See https://jazz.net/jazz/resource/itemName/com.ibm.team.workitem.WorkItem/158182.

Comment 8 is most relevant. You should use 'scm login' whenever possible (since it relies on filesystem permissions to prevent your password from leaking).

e

permanent link
Harel Fishgrund (2622) | answered Aug 31 '11, 2:01 p.m.
Thanx guys, I'll give it a try :)

Your answer


Register or to post your answer.


Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.