Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

MSSQL Clear Text password

Mark Hodges October 5, 2017

During a recent security audit, the auditors were able to capture the connection to the SQL server from the confluence application as it is using a clear text connection to the database.

Username: confluencedbo

Service: MSSQL

 

How do I configure confluence not to use a plain text connection to the SQL server?

1 answer

0 votes
Dave Theodore [Coyote Creek Consulting]
Community Champion
October 5, 2017

Is the issue that the database schema name and login creds are in plain text in the confluence.cfg.xml file on disk?

Or are they concerned about the traffic between the application and the database being unencrypted?

If the latter, the JTDS driver and MS SQL Server both support encryption. It's just a matter of setting it up.  If the former, there is nothing that is Atlassian supported that will help with this. 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events