pretty much any mechanism you use will be snoopable by root, so bear this in mind.
The echo option, will display in the 'ps' listings, making it vulnerable to ordinary users snooping and finding the password.
You can use -pass file:filename to use a file, so you can use:
sumask=$(umask)
umask 077
rm -f passfile
cat >passfile <<EOM
someGoodPassword
EOM
umask $sumask
this creates the file, unreadable by other accounts (but still readable by root). One assumes that the script is being used once only to create the passfile, as if you repeat the process, it tends to be in a file, and therefore you need to chmod go-rwx the file to make it unreadable by other users.
then you use:
openssl aes-256-cbc -a -salt -in twitterpost.txt -out foo.enc -pass file:passfile
to perform the encryption, using the pre-created password file.
Other mechanisms are -pass env:ENVVAR for using an environment variable (again getting it in there without revealing it is the trick)
answered 2011-06-12T10:53:10.213