# PMM2-Agent Keeping PMM2-Server Config username & password in Plain Text

**URL:** <https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475>\
**Category:** PMM 2.x\
**Created:** [December 14, 2021, 12:07pm UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475 "2021-12-14T12:07:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![simson.rif](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@simson.rif](https://forums.percona.com/u/simson.rif)\
**Post date:** [December 14, 2021, 12:07pm UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475/1 "2021-12-14T12:07:39Z")

</div>

Hi Team,  
Recently I’ve configured PMM2-Agent on one of my DB server to monitor it from PMM2-Server Dash board. During configuring my pmm2-agent I need to provide admin username & password of pmm2-server dashboard to register pmm2-agent. But PMM2-Agent keeping this username, password & server info in plain text. How can I get rid of pmm2-agent saving password in plain text ?

Is there any way to encrypt password in agent configuration file ?

This my Agent Config File:

```auto
[root@ config]# cat pmm-agent.yaml
# Updated by `pmm-agent setup`.
---
id: /agent_id/b..
listen-address: 127.0.0.1
listen-port: 7777
server:
    address: IP:443
    username: testuser
    password: TestPass245
    insecure-tls: true
paths:
    paths_base: /usr/local/percona/pmm2
    exporters_base: /usr/local/percona/pmm2/exporters
    node_exporter: /usr/local/percona/pmm2/exporters/node_exporter
    mysqld_exporter: /usr/local/percona/pmm2/exporters/mysqld_exporter
    mongodb_exporter: /usr/local/percona/pmm2/exporters/mongodb_exporter
    postgres_exporter: /usr/local/percona/pmm2/exporters/postgres_exporter
    proxysql_exporter: /usr/local/percona/pmm2/exporters/proxysql_exporter
    rds_exporter: /usr/local/percona/pmm2/exporters/rds_exporter
    azure_exporter: /usr/local/percona/pmm2/exporters/azure_exporter
    vmagent: /usr/local/percona/pmm2/exporters/vmagent
    tempdir: /tmp
    pt_summary: /usr/local/percona/pmm2/tools/pt-summary
    pt_pg_summary: /usr/local/percona/pmm2/tools/pt-pg-summary
    pt_mysql_summary: /usr/local/percona/pmm2/tools/pt-mysql-summary
    pt_mongodb_summary: /usr/local/percona/pmm2/tools/pt-mongodb-summary
ports:
    min: 42000
    max: 51999
debug: false
trace: false

```

---

<div class="post-metadata">

**Author:** ![Harry\_Geffin](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/harry_geffin/32/4039_2.png) [@Harry\_Geffin](https://forums.percona.com/u/Harry_Geffin)\
**Post date:** [January 5, 2022, 2:18pm UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475/2 "2022-01-05T14:18:31Z")

</div>

Hello Ferdous,  
In the web documentation, there is a section on enabling both HTTP password protection and SSL encryption, which may help:

> **[Percona Monitoring and Management](https://www.percona.com/doc/percona-monitoring-and-management/1.x/security.html)**
>
> Percona Monitoring and Management

“Combining Security Features…You can enable both HTTP password protection and SSL encryption by combining the corresponding options” .It may be an alternative solution to the problem  
Harry

---

<div class="post-metadata">

**Author:** ![tayeen.sslwireless](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@tayeen.sslwireless](https://forums.percona.com/u/tayeen.sslwireless)\
**Post date:** [January 18, 2022, 9:08am UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475/3 "2022-01-18T09:08:54Z")

</div>

Hello,  
What you have shared is the documentation of Percona v1. What about v2? Also, why is _ **pmm-agent.yaml** _ showing password in the first place? Is there any way around to avoid it?

---

<div class="post-metadata">

**Author:** ![Harry\_Geffin](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/harry_geffin/32/4039_2.png) [@Harry\_Geffin](https://forums.percona.com/u/Harry_Geffin)\
**Post date:** [January 18, 2022, 2:23pm UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475/4 "2022-01-18T14:23:55Z")

</div>

Hello Tayeen,  
The link above is for both PMM1 & 2 (dropdown box) - this link takes you directly to PMM 2: [Percona Monitoring and Management](https://www.percona.com/doc/percona-monitoring-and-management/2.x/index.html) - sorry for any confusion…I believe it still works the same way in PMM2.x…can anyone confirm this?

---

<div class="post-metadata">

**Author:** ![tayeen.sslwireless](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@tayeen.sslwireless](https://forums.percona.com/u/tayeen.sslwireless)\
**Post date:** [January 19, 2022, 6:56am UTC](https://forums.percona.com/t/pmm2-agent-keeping-pmm2-server-config-username-password-in-plain-text/13475/5 "2022-01-19T06:56:12Z")

</div>

Thanks. I apologize for the delayed response btw.
