BIND 10 #2713: b10-cmdctl-usermgr's prompts should be revisited

BIND 10 Development do-not-reply at isc.org
Tue Feb 26 13:52:36 UTC 2013


#2713: b10-cmdctl-usermgr's prompts should be revisited
-------------------------------------+-------------------------------------
            Reporter:  muks          |                        Owner:  jelte
                Type:  defect        |                       Status:
            Priority:  medium        |  reviewing
           Component:  cmd-ctl       |                    Milestone:
            Keywords:                |  Sprint-20130305
           Sensitive:  0             |                   Resolution:
         Sub-Project:  DNS           |                 CVSS Scoring:
Estimated Difficulty:  4             |              Defect Severity:  N/A
         Total Hours:  0             |  Feature Depending on Ticket:
                                     |          Add Hours to Ticket:  0
                                     |                    Internal?:  0
-------------------------------------+-------------------------------------

Comment (by jreed):

 Replying to [comment:6 jinmei]:

 > - maybe we should discourage typing in password as a command-line
 >   argument (because in theory it could be visible to others via ps(1)
 >   etc)?

 I agree we should discourage this.  I should have mentioned earlier but
 maybe we shouldn't have added that feature that way in the first place.  A
 common way is to refer to some named pipe, or file descriptor, or a file
 that contains the passphrase, etc.

-- 
Ticket URL: <http://bind10.isc.org/ticket/2713#comment:8>
BIND 10 Development <http://bind10.isc.org>
BIND 10 Development


More information about the bind10-tickets mailing list