Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-667

Database credentials are stored in clear text in configuration files.

XMLWordPrintable

      External system credentials (such as database) are stored in clear text in configuration files for deployed applications. Several options exist to mitigate the risk:

      1) Ensure tight file permissions are applied to the configuration files in each deployment. The documentation should be updated to reflect this need.
      2) Encrypt the values in files and do the decryption on application start up.

              Unassigned Unassigned
              wilhelmi Nathan Wilhelmi (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: