Issue Details (XML | Word | Printable)

Key: JRA-11144
Type: Improvement Improvement
Status: Open Open
Priority: Major Major
Assignee: Unassigned
Reporter: Jeff Turner [Atlassian]
Votes: 2
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
JIRA

Don't send passwords in emails when External password/user management enabled

Created: 20/Sep/06 12:56 AM   Updated: 26/May/08 06:15 AM
Component/s: Email integration, User Management
Affects Version/s: None
Fix Version/s: None

Time Tracking:
Not Specified

Participants: Jeff Turner [Atlassian]
Since last comment: 2 years, 2 weeks, 4 days ago
Support reference count: 3
Labels:


 Description  « Hide
In Admin -> General Configuration, there is an External password management flag which we recommend people turn on when using LDAP. In this case, when new users are created, it makes no sense to send the password in the email notification, since the password is unused (the LDAP password takes precedence). In fact, if users are self-registering and may enter their LDAP password, this is a security risk, as we don't want valid passwords going over unencrypted email.

For people using JIRA currently, passwords in signup emails can be prevented by editing:

atlassian-jira/WEB-INF/classes/templates/email/text/includes/userdetails.vm



 All   Comments   Work Log   Change History      Sort Order: Ascending order - Click to sort in descending order
There are no comments yet on this issue.