code, ipmi, security

… passwords in shell scripts….

Looking at a file (

# This script is run on every iDRAC at manufacturing time.
# to create a certificate with a derived CN using the
# service tag so it can be authenticated by a provisioning server
# for zero touch deployment.
# Files used:
# 1) d_h_ssl_manuf.cnf
# 2) ROOTCAPK.PEM (loaded by mdiags via dynamic partition)

#decrypt the signing key
if ! openssl base64 -d -in $ENCRYPTED_CA_PRIV_KEY -out $CA_PRIV_KEY \
-pass pass:zrPhlYx

Nice password, Dell… now to find ROOTCAPK.PEM and I’ll be set….