Todo #10349
closed
status.php: Sanitize ldapbindpass and ldap_pass
Added by Viktor Gurov over 4 years ago.
Updated over 4 years ago.
Description
config-sanitized.xml contains clear-text passwords:
<ldapbindpass> - squidguard LDAP DN Password (squidguard.xml)
<ldap_pass> - squid LDAP Password (squid_auth.xml)
- Status changed from New to Pull Request Review
- Tracker changed from Bug to Todo
- Project changed from pfSense Packages to pfSense
- Category changed from Squid to Diagnostics
- Assignee set to Jim Pingle
- Target version set to 2.5.0
- Status changed from Pull Request Review to Feedback
- % Done changed from 0 to 100
PR has been merged. Thanks!
OK on 2.5.0.a.20200323.0902:
# grep "ldap.*pass" /cf/conf/config.xml
<ldap_pass>123456</ldap_pass>
<ldapbindpass>123</ldapbindpass>
# grep "ldap.*pass" config-sanitized.xml
<ldap_pass>xxxxx</ldap_pass>
<ldapbindpass>xxxxx</ldapbindpass>
Renato Botelho wrote:
PR has been merged. Thanks!
- Status changed from Feedback to Resolved
- Private changed from Yes to No
- Status changed from Resolved to Feedback
- Target version changed from 2.5.0 to 2.4.5-p1
- Subject changed from Sanitize ldapbindpass and ldap_pass to status.php: Sanitize ldapbindpass and ldap_pass
- Status changed from Feedback to Resolved
Fields are in the list to sanitize.
Also available in: Atom
PDF