FYI: xi config snapshots may contain sensitive security info

This support forum board is for support questions relating to Nagios xi, our flagship commercial network monitoring solution.
cleu
Posts: 1
Joined: Fri Jan 06, 2012 2:53 pm

FYI: xi config snapshots may contain sensitive security info

Post by cleu »

Please be forewarned: If you supply the Nagios xi Customer Support team with a configuration snapshot, it may contain sensitive security information about your company's servers and applications. A configuration snapshot contains all of the files for your Nagios xi configuration (including the file 'resource.cfg' which may contain sensitive information such as usernames, passwords, etc). Thus prior to submitting a configuration snapshot, it is a good practice to first examine the snapshot, and if it contains potentially sensitive security information, such information be edited/X'ed out.
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises

Re: FYI: xi config snapshots may contain sensitive security

Post by scottwilkerson »

This is correct, the full snapshot does contain the resource.cfg file which as pointed out, could contain sensitive information. When submitting a snapshot, feel free to remove/obfuscate any sensitive information if it does not relate to diagnosing your problem.
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart