# Liquibase hiding or allowing encrypted password

**URL:** <https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050>\
**Category:** General Discussion\
**Created:** [October 23, 2021, 4:06pm UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050 "2021-10-23T16:06:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![liquibase\_rah](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@liquibase\_rah](https://forum.liquibase.org/u/liquibase_rah)\
**Post date:** [October 23, 2021, 4:06pm UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050/1 "2021-10-23T16:06:31Z")

</div>

Hi, I am using command line to pass the mysql clear text password to Liquibase on our AWS EC2 Linux servers. The same password is displayed via **ps** command. Is there a way to somehow either use encrypted password with Liquibase or hide this password when someone uses **“ps -ef”** command?

---

<div class="post-metadata">

**Author:** ![daryldoak](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/daryldoak/32/764_2.png) [@daryldoak](https://forum.liquibase.org/u/daryldoak)\
**Post date:** [October 25, 2021, 6:07pm UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050/2 "2021-10-25T18:07:52Z")

</div>

Put the username and password into a liquibase.properties file, then it will not show in a ps.

[https://docs.liquibase.com/workflows/liquibase-community/creating-config-properties.html](https://docs.liquibase.com/workflows/liquibase-community/creating-config-properties.html)

---

<div class="post-metadata">

**Author:** ![liquibase\_rah](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@liquibase\_rah](https://forum.liquibase.org/u/liquibase_rah)\
**Post date:** [October 25, 2021, 6:26pm UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050/3 "2021-10-25T18:26:07Z")

</div>

Thanks. But password in the properties file on disk is in clear text which is still unsafe as it can be read. Is there a way to allow Liquibase to use encrypted password in that file or command line like MySql mask the password given in command line so that in “ps -ef” it shows as all stars?

---

<div class="post-metadata">

**Author:** ![daryldoak](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/daryldoak/32/764_2.png) [@daryldoak](https://forum.liquibase.org/u/daryldoak)\
**Post date:** [October 26, 2021, 1:16pm UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050/4 "2021-10-26T13:16:52Z")

</div>

Permissions on the liquibase.properties file needs to be set appropriately for your needs. As far as I know there is no ability to encrypt the password on the command line.

---

<div class="post-metadata">

**Author:** ![sehzpaul97](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@sehzpaul97](https://forum.liquibase.org/u/sehzpaul97)\
**Post date:** [July 31, 2023, 6:35am UTC](https://forum.liquibase.org/t/liquibase-hiding-or-allowing-encrypted-password/6050/5 "2023-07-31T06:35:39Z")

</div>

@liquibase_rah and @daryldoak You should look into using `propertyProviderClass` provided by Liquibase now - [Create and Configure a liquibase.properties File](https://docs.liquibase.com/concepts/connections/creating-config-properties.html)  
Some helpful links -

1. [java - propertyProviderClass custom implementation with Jasypt not working - Stack Overflow](https://stackoverflow.com/questions/37325560/propertyproviderclass-custom-implementation-with-jasypt-not-working)
2. https[:][/][/]liquibase[.]jira[.]com/browse/CORE-1932

PS: I can’t add more than 2 links so just extract the link. Remove .
