6.11 Client password - '/etc/mysql/my.cnf password does not exist'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The use of this parameter may negatively impact the confidentiality of the user's password. The [Client] section of the MySQL configuration file allows setting a password to be used. Verify this option is not used.

Solution

Do not use password= configuration option

See Also

https://workbench.cisecurity.org/files/1613

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv6|16.13, CSCv6|16.14

Plugin: Unix

Control ID: fa12ee9c3f1fd1156a5aa0c49e8517b014e1a45c4f6b21f456f2a3024a0e9223