password security in an iApp

In iApps you can include password fields which is nice.

These passwords are retained when you reconfigure the app, which is even nicer.

But how are they protected ?
Are they also stored in the 'secure vault' ?


2 Answer(s):

Hello Bram,

Unfortunately, the values provided for "password" fields in iApps are not encrypted (or even obfuscated) as they are stored on disk. The UI hides it when you are viewing the template, but that's as far as it goes. You can see this for yourself via tmsh by running:

list sys application service

Substitute both instances of "myservice" in that command with the name you chose for the iApp service when you completed the form. That command will show you the configuration for the application, including its variables which will contain the plaintext of the password.

If this is an issue for you, I would encourage you to open a support case and ask for a Request for Enhancement (RFE) stating your expectations and desires.

Hi Brent,

thank you for your answer.
I see there is also a bigip_script.conf that contains the passwords in plain text.
I am going to launch that RFE.


Your answer: