Re: Login with blank password - Mailing list pgsql-admin

From Tom Lane
Subject Re: Login with blank password
Date
Msg-id 16621.1102782761@sss.pgh.pa.us
Whole thread Raw
In response to Login with blank password  (rray@tcmail.mstc.state.ms.us)
List pgsql-admin
rray@tcmail.mstc.state.ms.us writes:
> Is there a setting in postgresql.conf that will log the password that's used to login with?

No (deliberately so).

> If I add "host    all         user        172.17.32.0       255.255.255.0     password"
> to pg_hba.conf the user can login with a blank password.
> If I add "host    all         user        172.17.32.1       255.255.255.255     password"
> to pg_hba.conf the user must enter a correct password.

This sounds to me like you are failing to consider the effects of the
order of entries in pg_hba.conf --- ie, in the first case the connection
is being caught by a TRUST-mode entry (or at least, not a password-based
one ... could be IDENT as well).  Don't forget to SIGHUP the postmaster
after editing pg_hba.conf, too.

            regards, tom lane

pgsql-admin by date:

Previous
From: Devrim GUNDUZ
Date:
Subject: Re: postgresql 7.4.1 SRPM
Next
From: Tom Lane
Date:
Subject: Re: Backup is too slow