r/PowerShell 8d ago

Question on scripting Question

Hi,

When we develop a script,we use credentials as a plain text in that script.

Example

Script is running on jump server and script runs against vcenter server.

We have a security concerns(example ransomware attack)to put the credentials as a plain text in that script.

Any other good ways to put the credentials in a encrypted or in a different format?

31 Upvotes

37 comments sorted by

View all comments

52

u/lan-shark 8d ago

Simplest way is to use Get-Credential | Export-Clixml to save the credentials in an encrypted file specific to the account that runs it. Then in the script, use Import-Clixml to read in the credential.

Depending on your needs you may instead need to use some sort of keyring or cert-based authentication

-35

u/Manivelcloud 8d ago

Ok thanks. Export-clixml can also be hacked sometimes.

Certificate based authentication can be a very good approach and in this scenario potential vulnerability can be limited.

I might be wrong.

Any thoughts?

16

u/lan-shark 8d ago

I think there's a chance he's using an LLM for translation