Re: BUG #16079: Question Regarding the BUG #16064

Поиск
Список
Период
Сортировка
Искать
От
Stephen Frost
Тема
Re: BUG #16079: Question Regarding the BUG #16064
Дата
Msg-id
20201221005825.GQ16415@tamriel.snowman.net
Ответ на
Список
Дерево обсуждения
BUG #16079: Question Regarding the BUG #16064 PG Bug reporting form <noreply@postgresql.org>
Re: BUG #16079: Question Regarding the BUG #16064 Stephen Frost <sfrost@snowman.net>
Re: BUG #16079: Question Regarding the BUG #16064 Thomas Munro <thomas.munro@gmail.com>
Re: BUG #16079: Question Regarding the BUG #16064 Stephen Frost <sfrost@snowman.net>
Re: BUG #16079: Question Regarding the BUG #16064 Magnus Hagander <magnus@hagander.net>
Re: BUG #16079: Question Regarding the BUG #16064 Stephen Frost <sfrost@snowman.net>
Re: BUG #16079: Question Regarding the BUG #16064 Stephen Frost <sfrost@snowman.net>
Greetings,

* Magnus Hagander (magnus@hagander.net) wrote:
> On Fri, Nov 15, 2019 at 5:42 AM Thomas Munro  wrote:
> > On Tue, Oct 29, 2019 at 4:48 AM Stephen Frost  wrote:
> > > Uh, the user's credentials certainly are sent to the PG server.
> >
> > Perhaps we should log a warning when PostgreSQL has received a
> > password over the network without SSL.  Perhaps we should log another
> > warning when PostgreSQL has sent a password over the network without
> > SSL.
> 
> For the old plaintext "password" method, we log a warning when we parse the
> configuration file.
> 
> Maybe we should do the same for LDAP (and RADIUS)? This seems like a better
> place to put it than to log it at every time it's received?

A dollar short and a year late, but ... +1.

Thanks,

Stephen
В списке pgsql-bugs по дате отправления
От: Andrey Borodin
Дата:
От: Michael Paquier
Дата:
FAQ