Re: md5 passwords and pg_shadow
От | Bruce Momjian |
---|---|
Тема | Re: md5 passwords and pg_shadow |
Дата | |
Msg-id | 200204251739.g3PHdf102297@candle.pha.pa.us обсуждение исходный текст |
Ответ на | Re: md5 passwords and pg_shadow (Tom Lane <tgl@sss.pgh.pa.us>) |
Список | pgsql-hackers |
Tom Lane wrote: > Neil Conway <nconway@klamath.dyndns.org> writes: > > IMHO, there are two separate processes going on here: > > The connection you are missing is that hashed password storage is > incompatible with crypt-style password transmission. If we force > hashed storage then the only password transmission style available > to pre-7.2 clients is cleartext. It's not at all clear that securing > the on-disk representation is a more important goal than wire security. > (Perhaps it is for some cases, but in other cases it's surely not.) > So the parameter variable is there to let the DBA choose which he's > more worried about. > > We should probably change the default setting for 7.3, but I don't > think we'll be able to force hashed storage of passwords in all > installations for awhile longer yet. If we change that default in 7.3, pg_dump reload will md5 encrypt the passwords supplied from 7.2. Is that OK, and we can require them to set it to 'false' if they want pre-7.2 crypt compatibility? If so, I can make the change. -- Bruce Momjian | http://candle.pha.pa.us pgman@candle.pha.pa.us | (610) 853-3000+ If your life is a hard drive, | 830 Blythe Avenue + Christ can be your backup. | Drexel Hill, Pennsylvania19026
В списке pgsql-hackers по дате отправления: