tracker issue : CF-4202002

select a category, or use search below
(searches all categories and all time range)
Title:

Passwords are written to lockdown_logs.txt

| View in Tracker

Status/Resolution/Reason: Closed/Fixed/Fixed

Reporter/Name(from Bugbase): Peter Freitag / ()

Created: 04/17/2018

Components: Installation/Config, Lockdown Installer

Versions: 2018

Failure Type: Incorrectly functioning

Found In Build/Fixed In Build: Public Beta / 309953

Priority/Frequency: Normal / All users will encounter

Locale/System: ALL / Win 2016

Vote Count: 1

Problem Description: When asked for the OS Administrator password it says "The password is not stored" but it ended up in the lockdown_logs.txt file.

It also writes the CF Admin passwords to this file in plain text.

Steps to Reproduce: Install IIS, CF run lockdown installer -- I did encounter an error during lockdown installer which I'll post as a separate issue, so I'm not sure if it always puts the password in the file or if only on error at this point. 

Actual Result:  Administrator OS password is written in plain text to the log file.

Expected Result: "The password is not stored"

Any Workarounds: You have to delete the password from the file - not ideal.

Attachments:

Comments:

We had deliberately printed these values till GM. Will be removing this now.
Comment by Kailash B.
27464 | April 18, 2018 04:26:49 AM GMT
FYI The passwords were also written to C:\ColdFusion2018\lockdown\cfusion\Logs\Adobe_ColdFusion_2018_Automated_Lockdown_Installer_Install_04_17_2018_20_23_37.log
Comment by Peter F.
27465 | April 18, 2018 06:22:24 PM GMT