Red Hat Bugzilla – Bug 1415652
IPA replica install log shows password in plain text
Last modified: 2017-08-01 05:44:33 EDT
Description of problem: [root@server1 ~]# ipa-replica-install -p SimpleSample123 Configuring client side components Using existing certificate '/etc/ipa/ca.crt'. Discovery was successful! Client hostname: server1.testrelm.test Realm: TESTRELM.TEST DNS Domain: testrelm.test IPA Server: server1.testrelm.test BaseDN: dc=testrelm,dc=test [root@server1 ~]# grep SimpleSample123 /var/log/ipareplica-install.log 2017-01-23T11:04:10Z DEBUG args=/usr/sbin/ipa-client-install --unattended --no-ntp --password SimpleSample123 Version-Release number of selected component (if applicable): ipa-server-4.4.0-12.el7.x86_64 How reproducible: 100% Steps to Reproduce: as above Actual results: Password show in plain text in log file Expected results: Password should be masked as other passwords are masked.
Upstream ticket: https://fedorahosted.org/freeipa/ticket/6633
Fixed upstream. master: 054c1e013aee6fdbee2e9966c32df02d91f0c2c1 replica install: do not log host OTP
ipa-server-4.5.0-14.el7.x86_64 - Verfied
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2304