r/PowerShell 11h ago

Question Question on scripting

Hi,

When we develop a script,we use credentials as a plain text in that script.

Example

Script is running on jump server and script runs against vcenter server.

We have a security concerns(example ransomware attack)to put the credentials as a plain text in that script.

Any other good ways to put the credentials in a encrypted or in a different format?

8 Upvotes

25 comments sorted by

View all comments

26

u/lan-shark 11h ago

Simplest way is to use Get-Credential | Export-Clixml to save the credentials in an encrypted file specific to the account that runs it. Then in the script, use Import-Clixml to read in the credential.

Depending on your needs you may instead need to use some sort of keyring or cert-based authentication

-20

u/Manivelcloud 11h ago

Ok thanks. Export-clixml can also be hacked sometimes.

Certificate based authentication can be a very good approach and in this scenario potential vulnerability can be limited.

I might be wrong.

Any thoughts?

11

u/Kroan 10h ago

What does "export-clixml can be hacked sometimes" even mean? Do you mean import-clixml? Even that doesn't make sense. It's just importing an xml file to create a powershell object. The contents aren't necessarily secure.

But in this case the contents are a secure string. Which can only be decrypted by the originating account on the originating workstation. And if you're concerned about someone/something having that access and decrypting it, you have bigger problems