Project

General

Profile

Bug #3325

AD Domain Admin password is stored in cleartext

Added by Anonymous almost 8 years ago. Updated almost 8 years ago.

Status:
Closed: Duplicate
Priority:
Critical
Assignee:
-
Category:
Middleware
Target version:
-
Severity:
New
Reason for Closing:
Reason for Blocked:
Needs QA:
Yes
Needs Doc:
Yes
Needs Merging:
Yes
Needs Automation:
No
Support Suite Ticket:
n/a
Hardware Configuration:
ChangeLog Required:
No

Description

The Active Directory join credentials entered in the AD configuration page are stored in cleartext in the database. This is usually a user with Domain Admin credentials and, in the grand majority of Windows installations, has Administrator privileges on every machine joined to the domain. Storing this data is a massive security breach and is completely unnecessary as those credentials should only be needed once ever to perform the domain join.


Related issues

Is duplicate of FreeNAS - Feature #1403: Active Directory admin password is stored in the config databaseClosed

History

#1 Updated by Anonymous almost 8 years ago

  • Status changed from Unscreened to Closed: Duplicate

Also available in: Atom PDF