# Password stored in world-readable plain text file

**URL:** <https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069>\
**Category:** PMM 1.x\
**Created:** [June 20, 2019, 7:56am UTC](https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069 "2019-06-20T07:56:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![normelton](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/normelton/32/1042_2.png) [@normelton](https://forums.percona.com/u/normelton)\
**Post date:** [June 20, 2019, 7:56am UTC](https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069/1 "2019-06-20T07:56:38Z")

</div>

So I’ve got the pmm-client installed on a handful of database servers. Love the statistics that it reports.

When I used pmm-admin to connect to add the mysql plugin, it asked for credentials. I provided the mysql root username & password on the command line (that seemed dirty). I see that the password is saved in /etc/init/pmm-mysql-metrics-42002.conf, which is world-readable. This seems super dirty.

I suspect I’m not configuring something right here. Is there a way to pass a --login-path? Or some other way to authenticate to the mysql server? Should I be setting up a “pmm” user with limited permissions?

I don’t see this in the documentation, but feel free to send me in the right direction if I missed something.

Thanks

Norman

---

<div class="post-metadata">

**Author:** ![normelton](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/normelton/32/1042_2.png) [@normelton](https://forums.percona.com/u/normelton)\
**Post date:** [June 20, 2019, 7:58am UTC](https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069/2 "2019-06-20T07:58:57Z")

</div>

Whoop whoop, now I see some documentation about pmm-admin creating a “pmm” user, here: [url][Percona Monitoring and Management](https://www.percona.com/doc/percona-monitoring-and-management/pmm-admin.html#pmm-admin-add-mysql-queries%5B/url%5D). I’ll give that a shot. Still seems dirty to be storing the password world-readable :-/.

Norman

---

<div class="post-metadata">

**Author:** ![Roma\_Novikov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/roma_novikov/32/1161_2.png) [@Roma\_Novikov](https://forums.percona.com/u/Roma_Novikov)\
**Post date:** [June 24, 2019, 1:30am UTC](https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069/3 "2019-06-24T01:30:54Z")

</div>

Hi [normelton](https://percona.vanillacommunities.com/profile/x/x/22543) !  
Yes, for now we have this “not good” solution about user/password. We know about this and this will be solved in PMM2 (see [URL=“[Percona Monitoring and Management (PMM) 2 Beta Is Now Available - Percona Database Performance Blog](https://www.percona.com/blog/2019/05/30/percona-monitoring-and-management-pmm-2-beta-is-now-available/)”][https://www.percona.com/blog/2019/05...now-available/[/URL]](https://www.percona.com/blog/2019/05...now-available/%5B/URL%5D) ).

---

<div class="post-metadata">

**Author:** ![JykkeDaMan](https://avatars.discourse-cdn.com/v4/letter/j/a9a28c/32.png) [@JykkeDaMan](https://forums.percona.com/u/JykkeDaMan)\
**Post date:** [April 19, 2021, 7:44am UTC](https://forums.percona.com/t/password-stored-in-world-readable-plain-text-file/7069/4 "2021-04-19T07:44:14Z")

</div>

Is this still a case with the current PMM 2.16? I just installed 2.15 last week and I can still see the pwd’s in clear text on the client configurations!

/usr/local/percona/pmm2/config/pmm-agent.yaml

```
server:
    address: 10.132.111.123:443
    username: <clear_text_username>
    password: <cleart_text_pwd>

```

ps:

`... remoteWrite_basicAuth_password=<clear_text_pwd> remoteWrite_basicAuth_username=<cleart_text_username>`
