When invoking maxctrl with explicit user name and password the password can be seen in the clear in ps output, e.g.:
$ maxctrl --user=admin --password=mariadb
|
...
|
$ ps aux | grep maxctrl
|
vagrant 1898 0.0 0.0 2608 536 pts/0 S+ 11:01 0:00 /bin/sh /usr/bin/maxctrl --user=admin --password=mariadb
|
vagrant 1899 4.3 2.8 603328 58004 pts/0 Sl+ 11:01 0:00 node /usr/share/maxscale/maxctrl/maxctrl.js --user=admin --password=mariadb
|
On the server side command line tools obfuscate password parameters so that they can't be retrieved from ps output, maxctrl should do the same:
$ mysql --user=repl --password=Secret23! --host=master
|
...
|
$ ps aux | grep mysql
|
vagrant 1999 0.0 0.4 20176 8912 pts/0 S+ 11:06 0:00 mysql --user=repl --password=x xxxxxxx --host=master
|
We should handle this consistently across all tools, including maxctrl.
- is blocked by
-
MXS-4553
Rewrite maxctrl
-
-
Open
{"report":{"fcp":1596.7999997138977,"ttfb":348,"pageVisibility":"visible","entityId":133363,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"2b260ece-68ff-4bdb-80f7-2149d92926be","navigationType":0,"readyForUser":1670.3999996185303,"redirectCount":0,"resourceLoadedEnd":1860.6999998092651,"resourceLoadedStart":372.7999997138977,"resourceTiming":[{"duration":702,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":372.7999997138977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":372.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1074.7999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":702.0999999046326,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":373.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":373.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1075.1999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":765.4000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":373.2999997138977,"connectEnd":373.2999997138977,"connectStart":373.2999997138977,"domainLookupEnd":373.2999997138977,"domainLookupStart":373.2999997138977,"fetchStart":373.2999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":373.2999997138977,"responseEnd":1138.6999998092651,"responseStart":1138.6999998092651,"secureConnectionStart":373.2999997138977},{"duration":814.1999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":373.5,"connectEnd":373.5,"connectStart":373.5,"domainLookupEnd":373.5,"domainLookupStart":373.5,"fetchStart":373.5,"redirectEnd":0,"redirectStart":0,"requestStart":373.5,"responseEnd":1187.6999998092651,"responseStart":1187.6999998092651,"secureConnectionStart":373.5},{"duration":817.8000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":373.69999980926514,"connectEnd":373.69999980926514,"connectStart":373.69999980926514,"domainLookupEnd":373.69999980926514,"domainLookupStart":373.69999980926514,"fetchStart":373.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":373.69999980926514,"responseEnd":1191.5,"responseStart":1191.5,"secureConnectionStart":373.69999980926514},{"duration":818,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":373.8999996185303,"connectEnd":373.8999996185303,"connectStart":373.8999996185303,"domainLookupEnd":373.8999996185303,"domainLookupStart":373.8999996185303,"fetchStart":373.8999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":373.8999996185303,"responseEnd":1191.8999996185303,"responseStart":1191.8999996185303,"secureConnectionStart":373.8999996185303},{"duration":818.0999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":374.19999980926514,"connectEnd":374.19999980926514,"connectStart":374.19999980926514,"domainLookupEnd":374.19999980926514,"domainLookupStart":374.19999980926514,"fetchStart":374.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":374.19999980926514,"responseEnd":1192.2999997138977,"responseStart":1192.2999997138977,"secureConnectionStart":374.19999980926514},{"duration":908,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":374.2999997138977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":374.2999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1282.2999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":818.2999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":374.5,"connectEnd":374.5,"connectStart":374.5,"domainLookupEnd":374.5,"domainLookupStart":374.5,"fetchStart":374.5,"redirectEnd":0,"redirectStart":0,"requestStart":374.5,"responseEnd":1192.7999997138977,"responseStart":1192.7999997138977,"secureConnectionStart":374.5},{"duration":907.7999997138977,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":374.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":374.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1282.3999996185303,"responseStart":0,"secureConnectionStart":0},{"duration":818.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":374.7999997138977,"connectEnd":374.7999997138977,"connectStart":374.7999997138977,"domainLookupEnd":374.7999997138977,"domainLookupStart":374.7999997138977,"fetchStart":374.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":374.7999997138977,"responseEnd":1193.5,"responseStart":1193.5,"secureConnectionStart":374.7999997138977},{"duration":1484.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":375.7999997138977,"connectEnd":375.7999997138977,"connectStart":375.7999997138977,"domainLookupEnd":375.7999997138977,"domainLookupStart":375.7999997138977,"fetchStart":375.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":375.7999997138977,"responseEnd":1860.2999997138977,"responseStart":1860.2999997138977,"secureConnectionStart":375.7999997138977},{"duration":1484.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":376,"connectEnd":376,"connectStart":376,"domainLookupEnd":376,"domainLookupStart":376,"fetchStart":376,"redirectEnd":0,"redirectStart":0,"requestStart":376,"responseEnd":1860.6999998092651,"responseStart":1860.6999998092651,"secureConnectionStart":376},{"duration":426.1000003814697,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1294.3999996185303,"connectEnd":1294.3999996185303,"connectStart":1294.3999996185303,"domainLookupEnd":1294.3999996185303,"domainLookupStart":1294.3999996185303,"fetchStart":1294.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":1294.3999996185303,"responseEnd":1720.5,"responseStart":1720.5,"secureConnectionStart":1294.3999996185303},{"duration":351.40000009536743,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1589.8999996185303,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1589.8999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1941.2999997138977,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":187,"responseStart":348,"responseEnd":349,"domLoading":370,"domInteractive":1895,"domContentLoadedEventStart":1895,"domContentLoadedEventEnd":1941,"domComplete":2553,"loadEventStart":2553,"loadEventEnd":2553,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1867.0999999046326},{"name":"bigPipe.sidebar-id.end","time":1868},{"name":"bigPipe.activity-panel-pipe-id.start","time":1868.1999998092651},{"name":"bigPipe.activity-panel-pipe-id.end","time":1871.0999999046326},{"name":"activityTabFullyLoaded","time":1956.5999999046326}],"measures":[],"correlationId":"29fc3700b42d9a","effectiveType":"4g","downlink":9.1,"rtt":0,"serverDuration":101,"dbReadsTimeInMs":13,"dbConnsTimeInMs":23,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
I would imagine that it's still an improvement over unencrypted passwords as you'd need access to the encryption keys in order to be able to use that password.
Perhaps we should consider not allowing passwords to be passed on the command line as it's inherently insecure. The environment of a process is hidden from users so MAXCTRL_USER and MAXCTRL_PASSWORD would be more secure.