ADSM-L

Re: Clear text passwords. Was: Automating dsmserv

2003-05-27 16:43:36
Subject: Re: Clear text passwords. Was: Automating dsmserv
From: "Marcel J.E. Mol" <marcel AT MESA DOT NL>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Tue, 27 May 2003 22:42:19 +0200
On Tue, May 27, 2003 at 04:06:32PM -0400, Stephen E. Bacher wrote:
> Justin Bleistein <justin.bleistein AT sungard DOT com> wrote:
>
> >any alternatives to running: "dsmserv" via batch mode with the:
> >
> >dsmadmc -id=login -pass=password syntax...
> >
> >I mean it's passwords in clear text so all someone has to do is cat that
> >file and your exposed... Any ideas on how to automate the client-server
> >interface (dsmadmc) without displaying the password anywhere?. Thanks!.
>
> A slight improvement on security would be something like:
>
>  dsmadmc -id=login -pass=`cat /private/tsm/password.txt`

As a normal user on this system do "ps -ef | grep dsm" and you'll
see the result of `cat /private/tsm/password.txt` ...

-Marcel
--
     ======--------         Marcel J.E. Mol                MESA Consulting B.V.
    =======---------        ph. +31-(0)6-54724868          P.O. Box 112
    =======---------        marcel AT mesa DOT nl                 2630 AC  
Nootdorp
__==== www.mesa.nl ---____U_n_i_x______I_n_t_e_r_n_e_t____ The Netherlands ____
 They couldn't think of a number,           Linux user 1148  --  counter.li.org
    so they gave me a name!  -- Rupert Hine  --  www.ruperthine.com