IBM Support

IJ05990: HISTORY IN UNIX CONTAINS UNENCRYPTED PASSWORDS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • In Impact 7.1 the passwords used on the commands to
    manipulate users and roles is stored in the bsh history with its
    unencrypted password
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All Impact Users                                             *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * The command-line tools for Netcool/Impact require passwords  *
    * to be entered as command line arguments. No alternative      *
    * input method is offered.                                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Since the command-line tools only accept passwords as
    command-line arguments, you must manually clear the terminal
    history if you want the password removed from the terminal
    history.
    

Problem conclusion

  • The following command line tools have been updated to support
    password prompts as an alternative to entering passwords on the
    command line.
    
    install/security/confAuth4LDAP
    install/security/confAuth4OMNIbus
    install/security/configImpactSSL
    install/security/configImpactSSO
    install/security/configUsersGroups
    bin/nci_add_service
    bin/nci_policy
    bin/nci_sendevent
    
    If the password argument is excluded from the command line call,
    then the tool will prompt you to enter in the password value.
    
    Note: The bin/nci_trigger tool does not support a password
    prompt as it already includes support for encrypted passwords.
    
    The fix for this APAR is contained in the following maintenance
    packages:
    |Fix Pack | 7.1.0-TIV-NCI-FP0014
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ05990

  • Reported component name

    NETCOOL/IMPACT

  • Reported component ID

    5724O59IS

  • Reported release

    710

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-04-27

  • Closed date

    2018-08-17

  • Last modified date

    2018-08-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • UNKNOWN
    

Fix information

  • Fixed component name

    NETCOOL/IMPACT

  • Fixed component ID

    5724O59IS

Applicable component levels

  • R710 PSY

       UP

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSHYH","label":"Tivoli Netcool\/Impact"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710"}]

Document Information

Modified date:
22 August 2021