Re: PostgreSQL Password Cracker - Mailing list pgsql-hackers

From Tom Lane
Subject Re: PostgreSQL Password Cracker
Date
Msg-id 16836.1041481079@sss.pgh.pa.us
Whole thread Raw
In response to Re: PostgreSQL Password Cracker  (Bruce Momjian <pgman@candle.pha.pa.us>)
Responses Re: PostgreSQL Password Cracker
List pgsql-hackers
Bruce Momjian <pgman@candle.pha.pa.us> writes:
> What do others think?  I am not sure myself.

There should definitely be someplace that recommends using SSL across
insecure networks (if there's not already).  But it doesn't seem to me
to qualify as a FAQ entry.  Somewhere in the admin guide seems more
appropriate.  Perhaps under Client Authentication?

Maybe someone could even put together enough material to create a whole
chapter on security considerations --- this is hardly the only item
worthy of mention.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: PostgreSQL Password Cracker
Next
From: Bruce Momjian
Date:
Subject: Re: PostgreSQL Password Cracker