Currently keystore and truststore passwords are stored in plaintext in the files so they can be viewed by people simply browsing the file The values stored in the rhq-server.properties and agent-configuration.xml files should be encrypted/obfuscated - we should have script similar to the generate-db-password.sh that will do this. See also Bug 1070262 and Bug 577239 (RHQ)
*** This bug has been marked as a duplicate of bug 1070262 ***