You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
Hi all
I just notiecd that Crowd (embedded version as well as standalone) stores passwords for directories and applications in clear text (table cwd_directory_attribute / ldap.password & application.password). I believe that is a big security issue so I wonder if there is a workaround available or if this is just a matter of configuration?
Thanks
Peter
There is an open Crowd issue for this - CWD-1876. However, if the password in the database is encrypted, this still leaves the problem of how to store the master key securely.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.