Warning Plain Text password on radius


we have privacyidea 2.19 with freeradius.

We have the following important problem.

All passwd on radius log (reffered to ad login password) are in clear text.

This is very dangerous.

Tue May 1 04:20:03 2018 : rlm_perl: urlparam client = x.x.x.x
Tue May 1 04:20:03 2018 : rlm_perl: urlparam pass = E1dxxxxxxxx
Tue May 1 04:20:03 2018 : rlm_perl: urlparam user = name.surname

Its possible to hide this passwd??

We have tried in different ways but nothing.

Thanks for all support!


This is our radius conf:

Dear Alessandro,

why not contribute something to the community you are using so excessively and try to provide a “patch” if you think that there is a problem.
I personally see no problem here, since the password only appears, under certain conditions.
And this is intentially…

Kind regards


To expand on Cornelius’ point: The URL parameters (and thus, the password) are only logged if the debug mode of the privacyIDEA plugin is explicitly enabled in the INI file. As they are only logged using FreeRADIUS Debug log level, they are only written to the logs if the FreeRADIUS server is configured to log debug messages. Both settings are definitely unfit for production scenarios.


Hi Fredreichbier,
your help has been greatly appreciated!

I’ ve setting debug mode to false in rlm_perl.ini e password now is hide.

Thanks a lot!


Sorry, mine did not want to be a polemical tone and in any case I could not issue a patch.
I just wanted to know if it was possible to hide the password from privacyidea logs.

Thanks anyway.

Kind Regards