Matt Mullins created CLOUDSTACK-8342:
----------------------------------------

             Summary: LDAP Password is unsecure in the Global Settings Page
                 Key: CLOUDSTACK-8342
                 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-8342
             Project: CloudStack
          Issue Type: Bug
      Security Level: Public (Anyone can view this level - this is the default.)
          Components: Management Server
    Affects Versions: 4.5.0, 4.4.0, 4.2.0
            Reporter: Matt Mullins


The setting for ldap.bind.password is showing as plain text in the global 
settings page. This password should be stared out (e.g. ************) to keep 
the password encrypted since these passwords are usually secure and kept 
private.

This should also stayed starred out when the edit is clicked on. The Admin can 
replace if necessary.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to