I would suggest raising this as a defect as this seems to be AR System
related and a security issue at that given that it might be necessary for
you from time to time to log more to the log file for obvious reasons.

I recall this being an issue with some other area a few versions ago - I do
not recall exactly what component but just like this, the log files would
document the password in clear text while troubleshooting problems or
debugging new code. A hot fix released in a reasonable time by engineering
took care of it which was then a part of the next patch..

You might be able to get engineering to work on a hot fix.

Cheers

Joe

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Oldershaw, Peter <CTR>
Sent: Tuesday, February 23, 2016 2:08 PM
To: arslist@ARSLIST.ORG
Subject: Re: Password visible in the arcarte.log file

AR System, for now.

Cheers...Peter
Infozen Contractor
703 447 5863


-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Joe D'Souza
Sent: Monday, February 22, 2016 6:12 PM
To: arslist@ARSLIST.ORG
Subject: Re: Password visible in the arcarte.log file

Just for my info, what method of authentication are you using?

Internal AR System?
LDAP Authentication?
SSO?

By any chance did you get a chance to switch between these methods and see
if you get the same result?

Cheers

Joe

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:arslist@ARSLIST.ORG] On Behalf Of Peter Oldershaw
Sent: Monday, February 22, 2016 3:26 PM
To: arslist@ARSLIST.ORG
Subject: Password visible in the arcarte.log file

Just wondered if others had noticed this.  We are on 9.0.01 and it seems
that the Smart Reporting User Sync job is set at a DEBUG log level. The
result is that the user ids and passwords are logged in plain text to the
log file. I set it to minimal to fix the problem.

Cheers...Peter

____________________________________________________________________________
___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org "Where the Answers
Are, and have been for 20 years"

____________________________________________________________________________
___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org
"Where the Answers Are, and have been for 20 years"

Reply via email to