mnagel
8 years agoProfessor
LMConfig Credentials Masking
Please consider either updating all ConfigSources to mask credentials when displayed (but perhaps leave them intact so full configurations can be reconstituted or displayed with a toggle if desired to see onscreen). In some cases, credentials are easily cracked (e.g., IOS type 7 encoded passwords or easily cracked IOS type 4 hashes) or are displayed in plaintext. Having that viewable by default by anyone with access is a potential security problem. See also previous request to increase granularity so this type of data can be excluded via RBAC settings.
Thanks,
Mark