Basically, we never looked at this as a security issue. Since SysAid usually runs on a server, the serverConf.xml file should not be accessible for domain users to see (limited by NTFS permissions).
The password showing on the configuration file was more of a cosmetic issue.
I hate to dig up an old ticket but the responses to peoples questions in this thread are inadequate.
We are being told to use a service account with read-only privileges, however for password services you ask that we use a domain administrator account. what is the correct answer? Domain admin or read-only user?
Hi @@@,
SysAid requires read-only permissions to import user data from AD and perform authentication. It requires a domain admin account if you are also implementing Password Services.
So did you ever notify your customers or do they only find out when they stumble across this post? Storing any password in plaintext is poor security and if you didn’t think this was an issue or worth notifying your clients about then what other “non-issues” are lurking out there for us to find?
SysAid Technologies Ltd.
Toll-Free phone center (U.S.): 1-800-686-7047
Offices - U.S.617-231-0124
Israel:+972-3-533-3675
Email:helpdesk@sysaid.com
Optimized by SEO Israel
SysAid logos and other SysAid Technologies marks
are trademarks or registered trademarks of
SysAid Technologies Ltd.
All Rights Reserved by SysAid Technologies Ltd.
2002-2011
Live Support Hours
07:00 AM - 09:30 PM (UK)
03:00 AM - 05:30 PM (EDT)
We provide worldwide services, and we do our best
to match the working times of customers from
different time zones.
SysAid Help Desk Software and Asset Management Software