Hi,
I'm sorry to read that your experience was not cool. Let me jump in here and take the chance to explain. First, there seems to be some confusion about the SG version in use.
The way that configuration settings (including usernames and passwords) are stored changed completely from SG1 to SG2. All SG settings are now stored in an secured index, making it possible to hot reload the configuration, and making sure that these sensitive informations do no leak. We surely understood your problem, but it applies to SG1 and not SG2. SG2 does not have this issue any more. That's why we wrote "there should not be any password there", referring to SG2. Sorry if this was not clear from our answer.
Regarding the discontinuation of SG1: We did announce that on a public post on Google Groups on 25th of February:
"We decided to take the project to the next level with the release of SG2 while at the same time slowly fading out the development for SG1. We will dedicate substantially more time and resources for SG2 in 2016, and provide new releases and support on a regular basis."
Agreed, we could have made this decision a little bit more prominent, and I take the blame for that.
I understand that the discontinuation might create some trouble for users who are not able to upgrade. But also understand that we neither have the financial power nor the development powers to maintain SG1/ES1, SG2/ES2 and (soon) SG5/SG5 at the same time.
SG1 is completely free (as in free beer), including the now dual licensed features like LDAP, Kerberos, DLS/FLS etc. The complete code has been contributed to the community, and we would be more than happy if the community would fork the repository and continued to provide patches and bug fixes for SG1. But since we do not get much requests for SG1 anymore, there are no sources of revenue from SG1, and we need to pay our developers, it was mandatory for us make this cut. Otherwise we would have not been able to continue with Search Guard
Please also read my post from 25th of February, explaining our decision a little bit more:
Thanks,
--
Jochen Kressin
CTO
floragunn UG (haftungsbeschränkt)
Tempelhofer Ufer 16
10963 Berlin