Learn F5 Technologies, Get Answers & Share Community Solutions
You are here:
Questions and Answers
+ Ask Question
password security in an iApp
In iApps you can include password fields which is nice.
These passwords are retained when you reconfigure the app, which is even nicer.
But how are they protected ?
Are they also stored in the 'secure vault' ?
Unfortunately, the values provided for "password" fields in iApps are not encrypted (or even obfuscated) as they are stored on disk. The UI hides it when you are viewing the template, but that's as far as it goes. You can see this for yourself via tmsh by running:
list sys application service myservice.app/myservice
Substitute both instances of "myservice" in that command with the name you chose for the iApp service when you completed the form. That command will show you the configuration for the application, including its variables which will contain the plaintext of the password.
If this is an issue for you, I would encourage you to open a support case and ask for a Request for Enhancement (RFE) stating your expectations and desires.
thank you for your answer.
I see there is also a bigip_script.conf that contains the passwords in plain text.
I am going to launch that RFE.
You must be logged in to reply. You can login
Specify an image to upload:
Your post has been identified as spam. If this is not the case, please contact
hint: access search faster by typing