Mailing List Archive

RANCID password filter
The RANCID docs say that the default for RANCID is to remove reversible
passwords from a configfile to avoid their being sent by email when
the diffs go out.

What if the diffs were filtered instead? Are there any other reasons
to keep passwords out of the config?
RANCID password filter [ In reply to ]
Thu, Jun 09, 2005 at 07:45:46PM -0400, Ed Ravin:
> The RANCID docs say that the default for RANCID is to remove reversible
> passwords from a configfile to avoid their being sent by email when
> the diffs go out.
>
> What if the diffs were filtered instead? Are there any other reasons
> to keep passwords out of the config?

This has come-up before. See share/rtrfilter for an example of how one
could do that.
RANCID password filter [ In reply to ]
> The RANCID docs say that the default for RANCID is to remove reversible
> passwords from a configfile to avoid their being sent by email when
> the diffs go out.
>
> What if the diffs were filtered instead? Are there any other reasons
> to keep passwords out of the config?

they would be stored in decodable text on disk

randy