# Encrypt or hide password from Jenkins.xml file: --httpsKeyStorePassword

**URL:** <https://community.jenkins.io/t/encrypt-or-hide-password-from-jenkins-xml-file-httpskeystorepassword/14901>\
**Category:** Community\
**Tags:** question\
**Created:** [May 7, 2024, 12:25pm UTC](https://community.jenkins.io/t/encrypt-or-hide-password-from-jenkins-xml-file-httpskeystorepassword/14901 "2024-05-07T12:25:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![parmeshwarjadhao](https://avatars.discourse-cdn.com/v4/letter/p/9e8a1a/32.png) [@parmeshwarjadhao](https://community.jenkins.io/u/parmeshwarjadhao)\
**Post date:** [May 7, 2024, 12:25pm UTC](https://community.jenkins.io/t/encrypt-or-hide-password-from-jenkins-xml-file-httpskeystorepassword/14901/1 "2024-05-07T12:25:05Z")

</div>

Is there a way to encrypt or hide password from Jenkins.xml file. Adding password in the configuration file is not recommended. We have password setup in the jenkins.xml file.

-Xrs -Xmx256m -Dhudson.lifecycle=hudson.lifecycle.WindowsServiceLifecycle -jar “C:\Program Files\Jenkins\jenkins.war” --httpPort=-1 --httpsPort=8443 --httpsKeyStore=“%ProgramData%\Jenkins.jenkins\secrets\jenkins-cert.jks” **–httpsKeyStorePassword** =\*\*\*\*\*\*\* --webroot=“%ProgramData%\Jenkins\war”

Is there any way to hide it.

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [May 7, 2024, 1:22pm UTC](https://community.jenkins.io/t/encrypt-or-hide-password-from-jenkins-xml-file-httpskeystorepassword/14901/2 "2024-05-07T13:22:12Z")

</div>

Yes, storing sensitive information like plain text passwords is not recommended for security reasons.

In Jenkins, you can use the [Jenkins Credential Plugin](https://plugins.jenkins.io/credentials/) to manage credentials securely.

However, in your case, it seems like you are trying to secure the password of the HTTPS keystore used by Jenkins when it’s started as a Windows service, right?

This password is needed at startup, so it must be available in plain text form at that time as far as I know.

One not-so-good approach to improve the security could be to restrict the access to the `jenkins.xml` file itself.  
You can set the file permissions such that only the user account that is used to run the Jenkins service can read this file.

That approach is far from perfect, but may work with PowerShell:

```auto
# Replace 'username' with the actual username of the account running the Jenkins service
$acl = Get-Acl 'C:\Program Files\Jenkins\jenkins.xml'
$acl.SetAccessRuleProtection($True, $False)
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule('username', 'FullControl', 'Allow')
$acl.AddAccessRule($rule)
Set-Acl 'C:\Program Files\Jenkins\jenkins.xml' $acl

```

This script will remove all permissions for the `jenkins.xml` file and then add ‘_FullControl_’ permission for the specified user.

Of course, this does not encrypt or hide the password 😢 , but it does restrict who can see it. 🤷

If an attacker gains access to the account that runs the Jenkins service, they will still be able to read this file.

My 💲0.02.

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [May 7, 2024, 2:49pm UTC](https://community.jenkins.io/t/encrypt-or-hide-password-from-jenkins-xml-file-httpskeystorepassword/14901/3 "2024-05-07T14:49:53Z")

</div>

you can put the parameters of Jenkins in a separate file and just pass this with  
`java <javaopt> -jar jenkins.war --config=c:\tools\jenkins.args`  
That way you at least avoid that the password is part of the running command and visible in the process tree.  
Depending on how the startup is actually implemented, jenkins could (via an init script maybe) delete the file afterwards. The startup process would need to ensure that the file is create each time before Jenkins starts.
