Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
encryption of password in rptdesign file and connectionprofile store
jar
<p>Hello,</p>
<p> </p>
<p>We are moving to a hosted version control system and are interested to known what kind of encryption is applied to the password that is stored in the .rptdesign and the .acconnprofiles file.</p>
<p> </p>
<p>We are using connection profiles for the database connection but we see that the odaURL, odaUser and odaPassword are stored in the .rptdesign file. As I understood it I expected this information to be stored in the connectionProfile.acconnprofiles file and that the .rptdesign would only link to it.</p>
<p>The odaPassword is encrypted but with what kind of encryption? </p>
<p> </p>
<p>I searched the site but I am unable to find a clear answer what kind of encryption is used by default. </p>
<p> </p>
<p>Any pointer to the right direction are appreciated ...</p>
<p> </p>
<p>Kind regards,</p>
<p>Jeroen</p>
Find more posts tagged with
Comments
PaulCooper
<p>I am not sure how passwords are stored in connection profiles as we use JNDI URLs in our JBoss based application so the password is stored in plain text on the server and the server maintains the connection. As for passwords you can put in the datasource (and you shouldn't use this except for development and testing and should make sure it is removed afterwards) they are stored in the file using base64 encoding which isn't encryption. (Unless you call things such as ROT13 encryption!) You can use online websites these days to decode base64. It usually tells you the "encryption" type as an attribute of the odaPassword element. These simple encodings really only serve to stop the password being casually readable.</p>