Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Encrypting DB credentials in conf/server.xml file when creating a data source

Ibrahiem Mohammad January 7, 2019

Hi,

I used this tutorial https://confluence.atlassian.com/doc/configuring-a-datasource-connection-937166084.html to create a data source which I can connect to from any plugins I create. I've tested the connection and everything is working fine.

 

My concern is regarding the safety of having my db username and passwords in plain text on my server. Is there any way I can encrypt that information in the server.xml file? If not, are there safer/more secure alternatives I can use?

Thanks

1 answer

1 accepted

1 vote
Answer accepted
Shannon S
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 9, 2019

Hello Ibrahiem,

We have a feature request below to support encryption of any passwords stored on the filesystem:

While a legitimate security concern, someone wouldn't be able to gain access to the server.xml file without first breaking into the file system. For this reason, you want to make sure your internal security team has protected your internal server sufficiently. Make sure that all passwords are secure, and if needed, place your server behind an internal firewall.

Please vote on the above feature request in order to show your support for such a feature, and comment with your findings and your usage case.

Take care, and do let me know if you have any further questions or concerns.

Regards,

Shannon

Ibrahiem Mohammad January 9, 2019

Thanks Shannon, will look into this

Like Shannon S likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events