{
    my $horderec = $DB->get('horde')
	|| $DB->new_record('horde', {type => 'service'});
    my $horde_pw = $horderec->prop('DbPassword');
    if (not $horde_pw or length($horde_pw) < 57)
    {
	use MIME::Base64 qw(encode_base64);

	$horde_pw = "not set due to error";
	if ( open( RANDOM, "/dev/urandom" ) )
	{
	    my $buf;
	    # 57 bytes is a full line of Base64 coding, and contains
	    # 456 bits of randomness - given a perfectly random /dev/random
	    if ( read( RANDOM, $buf, 57 ) != 57 )
	    {
		warn("Short read from /dev/random: $!");
	    }
	    else
	    {
		$horde_pw = encode_base64($buf);
		chomp $horde_pw;
	    }
	    close RANDOM;
	}
	else
	{
	    warn "Could not open /dev/urandom: $!";
	}
	$horderec->set_prop('DbPassword', $horde_pw);
    }
}
