[Freeipa-devel] [PATCH] 881 don't log OTP in client install log

Martin Kosek mkosek at redhat.com
Fri Sep 23 13:19:49 UTC 2011


On Fri, 2011-09-23 at 09:07 -0400, Rob Crittenden wrote:
> Martin Kosek wrote:
> > On Thu, 2011-09-22 at 11:55 -0400, Rob Crittenden wrote:
> >> Obfuscate the one-time password in the client installer log.
> >>
> >> rob
> >
> > NACK. You missed a case when OTP is interactively prompted (-W parameter
> > is passed).
> >
> > Martin
> >
> 
> Nice catch, updated patch
> 
> rob

Umh, nice try. I think you wanted to read nolog password from
getpass.getpass output and not options.password.

Martin




More information about the Freeipa-devel mailing list