I don't think storing passwords in any format in source control is good. Like someone else said, it's mixing app logic with deployment.
We use a combination of Google's open source Keyczar [1] and a relatively new Python keyring [2] library which uses the Keyczar crypter to read/write keys to a keyring storage backend, where the backend interface can be implemented with local crypted files or a cloud service.
[1] http://www.keyczar.org/
[2] http://pypi.python.org/pypi/keyring
We built this Python wrapper called appauth around of the concept of a Keyring service by application domain.
e.g. pseudo code:
import appauth
auth_service = appauth.AuthService('my-web-app')
db_creds_cfg = auth_service.get('primary-db')
Inside of db_creds_cfg, it can be a free-form dictionary that provides whatever details is needed to get into a resource:
db_creds_cfg['db_host']
db_creds_cfg['db_port']
db_creds_cfg['username']
db_creds_cfg['password']
I put in some honest effort to find an open source solution to this, but failed to find anything with a simple install process AND programming interface. Is there any interest from HN if we choose to open source this?
Furthermore, we use Google Authenticator on our servers to require two-factor auth: http://code.google.com/p/google-authenticator/, on top of disabling password auth in favor of signing in with ssh keys. All log files are then either set to permission 600 just to be super paranoid.