www-servers/tomcat: generate a more secure password
authorJulian Ospald <hasufell@gentoo.org>
Mon, 26 Oct 2015 20:17:23 +0000 (21:17 +0100)
committerJames Le Cuirot <chewi@gentoo.org>
Tue, 27 Oct 2015 13:10:03 +0000 (13:10 +0000)
www-servers/tomcat/tomcat-8.0.28-r1.ebuild

index a06fb32f81057fefb9da2bb9494f0a39edd22563..0d40f89e880ffe7813c834d5f0c1217241921e71 100644 (file)
@@ -31,6 +31,7 @@ RDEPEND="${COMMON_DEP}
        !<dev-java/tomcat-native-1.1.24
        >=virtual/jre-1.7"
 DEPEND="${COMMON_DEP}
+       app-admin/pwgen
        >=virtual/jdk-1.7
        test? (
                >=dev-java/ant-junit-1.9:0
@@ -110,7 +111,7 @@ src_install() {
        fperms 0750 "${dest}"/logs
 
        # replace the default pw with a random one, see #92281
-       local randpw=$(echo ${RANDOM}|md5sum|cut -c 1-15)
+       local randpw="$(pwgen -s -B 15 1)"
        sed -i -e "s|SHUTDOWN|${randpw}|" output/build/conf/server.xml || die
 
        # prepend gentoo.classpath to common.loader, see #453212