ServiceControl can send health check notifications by email. To authenticate with the SMTP server, ServiceControl stores the SMTP account and password in its database.
How the password is handled
- The password is stored in the ServiceControl database. Everyone who can read that database can read the password.
- From ServiceControl version 6.21.2, the API never returns the stored password. In ServicePulse, the password field is empty, even when a password is stored.
- Leave the password field empty to keep the stored password, or enter a new password to replace it.
- To remove the stored password, clear the authentication account.
Securing the SMTP account
To limit the damage if the password is disclosed:
- Use a dedicated SMTP account for ServiceControl notifications. Do not use an account that people or other applications also use.
- Limit what the account can send: only from the configured From address, and only to the configured To addresses.
- Limit access to the ServiceControl database:
- With the RavenDB persister in a container, do not expose the RavenDB port outside the container network.
- With the SQL Server or PostgreSQL persister, grant database access only to the ServiceControl instance and to administrators.
- Change the password of the SMTP account if it might have been disclosed.