Hi Alfred,

If you upgrade to the 2.0 releases, all passwords will be encrypted. I know 
it's not trivial, and maybe we can backport that to a 1.7 release, but as we're 
about to start on the 2.5 betas, we're unlikely to continue making major 
changes to 1.7 from here on out. We'll see what we can do though.

Christian

--  
Christian Hammond - christ...@beanbaginc.com  
Review Board - https://www.reviewboard.org  
Beanbag, Inc. - https://www.beanbaginc.com

-----Original Message-----
From: Alfred von Campe <alf...@von-campe.com>
Reply: reviewboard@googlegroups.com <reviewboard@googlegroups.com>>
Date: February 20, 2015 at 12:07:29 PM
To: reviewboard@googlegroups.com <reviewboard@googlegroups.com>>
Subject:  Subversion access via https:// and plaintext passwords

> We have been using ReviewBoard with our Subversion repos using svn+ssh:// 
> access, and  
> while functional, it’s been a little slow. Performance with https:// access 
> to our Subversion  
> servers is noticeably faster, but when I configure the Repository in 
> ReviewBoard and  
> specify the username and password to use, I noticed that the password is 
> stored in plain  
> text in the database. The database itself is not easily accessible by users, 
> but the nightly  
> database dumps could be read by others, so I am concerned about a possible 
> exposure of  
> automated build user account password.
>  
> We are still using ReviewBoard 1.7.27 as it is hosted on a CentOS 6 server, 
> so upgrading  
> to 2.X is not trivial. Is it common practice for ReviewBoard users to store 
> repository  
> passwords in the database in plain text?
>  
> Alfred
>  
>  
> --
> Supercharge your Review Board with Power Pack: 
> https://www.reviewboard.org/powerpack/  
> Want us to host Review Board for you? Check out RBCommons: 
> https://rbcommons.com/
> Happy user? Let us know! https://www.reviewboard.org/users/
> ---
> You received this message because you are subscribed to the Google Groups 
> "reviewboard"  
> group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to reviewboard+unsubscr...@googlegroups.com.  
> For more options, visit https://groups.google.com/d/optout.
>  

-- 
Supercharge your Review Board with Power Pack: 
https://www.reviewboard.org/powerpack/
Want us to host Review Board for you? Check out RBCommons: 
https://rbcommons.com/
Happy user? Let us know! https://www.reviewboard.org/users/
--- 
You received this message because you are subscribed to the Google Groups 
"reviewboard" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to reviewboard+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to