Skip to content

SYSDBA password in SYSDBA.password is a build-time constant shared by all containers of an image #48

Description

@fdcastel

Follow-up from the "Additional note" in #47.

Problem

When FIREBIRD_ROOT_PASSWORD is not set, the SYSDBA password is the one generated by the Firebird installer at image build time and stored in /opt/firebird/SYSDBA.password. Since it is baked into an image layer, every container created from the same image shares the same SYSDBA password, and anyone who can pull the image can read it:

$ docker run --rm firebirdsql/firebird:5.0.4 grep ISC_PASSWORD= /opt/firebird/SYSDBA.password
ISC_PASSWORD=XLFzVzEW6oC8KrLqgZ59
$ docker run --rm firebirdsql/firebird:5.0.4 grep ISC_PASSWORD= /opt/firebird/SYSDBA.password
ISC_PASSWORD=XLFzVzEW6oC8KrLqgZ59

This affects Firebird 4 and 5 images today. Firebird 3 images were not affected only because the generated password was never actually set (#47); once that is fixed, they will behave the same way.

The README describes this password as a "one-off password", which suggests it is unique per installation. For a container started with port 3050 published and without FIREBIRD_ROOT_PASSWORD, SYSDBA is effectively protected by a publicly known password.

Proposal

When FIREBIRD_ROOT_PASSWORD is not set, generate a new random SYSDBA password on the container's first start (in entrypoint.sh), set it via CREATE OR ALTER USER SYSDBA ... USING PLUGIN Srp, and write it to /opt/firebird/SYSDBA.password (same format as today), so that each container gets its own password. The generated password could also be printed to the container log, similar to what the official MySQL image does with MYSQL_RANDOM_ROOT_PASSWORD, so users can retrieve it with docker logs.

Notes:

  • The security database lives in /opt/firebird (the container's writable layer, not the data volume), so "first start" means once per container: restarts of the same container must keep the password, while a recreated container gets a new one.
  • The behaviour when FIREBIRD_ROOT_PASSWORD is set stays unchanged.
  • FIREBIRD_USE_LEGACY_AUTH=true should get the same treatment as the existing set_sysdba() (also set the password with Legacy_UserManager).
  • The README section for FIREBIRD_ROOT_PASSWORD should be updated to describe the new behaviour.

Activity

  1. fdcastel commented on Sep 26, 2026

    @fdcastel
    MemberAuthor

    This is implemented in #52, and an unofficial test image is available. Feedback from anyone following this issue is welcome.

    Unofficial test image

    ghcr.io/fdcastel/firebird (Debian Trixie, amd64), with tags 5 / 5.0.4, 4 / 4.0.7 and 3 / 3.0.14. It is for testing only: it is built from a branch that combines #52 with #49 (issue #47) and #51 (issue #46).

    How it works

    • If FIREBIRD_ROOT_PASSWORD is set, nothing changes: SYSDBA gets that password.
    • Otherwise, on the container's first start, the entrypoint generates a random 20-character password and sets it for SYSDBA (also with Legacy_UserManager when FIREBIRD_USE_LEGACY_AUTH=true). It stores the password in /opt/firebird/SYSDBA.password, in the same format the Firebird installer uses.
    • The password itself is never printed to the container log. The log only says where it is stored:
      Generating random SYSDBA password.
      SYSDBA password stored in /opt/firebird/SYSDBA.password.
      
    • "First start" is detected by comparing the security database with a checksum recorded at image build time. Restarting the same container keeps its password, and a recreated container gets a new one.
    • A security database that was already changed, for example one bind-mounted by the user, is never touched.
    • Note: Legacy_Auth only checks the first 8 characters of a password (a Firebird limitation).

    Examples

    docker run -d --name fb -p 3050:3050 ghcr.io/fdcastel/firebird:5
    docker logs fb
    docker exec fb cat /opt/firebird/SYSDBA.password
    
    # Restarting keeps the password
    docker restart fb && docker exec fb grep ISC_PASSWORD= /opt/firebird/SYSDBA.password
    
    # A new container gets a different password
    docker run -d --name fb2 ghcr.io/fdcastel/firebird:5
    docker exec fb2 grep ISC_PASSWORD= /opt/firebird/SYSDBA.password

    Connecting with the generated password:

    PW=$(docker exec fb awk -F= '/^ISC_PASSWORD/{print $2}' /opt/firebird/SYSDBA.password)
    docker exec fb bash -c "echo \"CREATE DATABASE 'localhost:/var/lib/firebird/data/test.fdb' USER 'SYSDBA' PASSWORD '$PW';\" | isql -q"

    Please test it with your usual setup (Docker, Compose, Kubernetes, bind-mounted security databases, FIREBIRD_USE_LEGACY_AUTH) and report back here, especially if the password is regenerated when you don't expect it, or is not regenerated when you do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions