Re: So we're in agreement.... - Mailing list pgsql-hackers

From Bruce Momjian
Subject Re: So we're in agreement....
Date
Msg-id 200005070321.XAA28233@candle.pha.pa.us
Whole thread Raw
In response to So we're in agreement....  (Vince Vielhaber <vev@michvhf.com>)
Responses Re: So we're in agreement....  (The Hermit Hacker <scrappy@hub.org>)
List pgsql-hackers
> 
> So we're in agreement on using MD5.   Sverre, is the offer still open
> for the java MD5 you wrote?  I'll translate it to C and make sure it
> will compile/run/give-correct-results on as many platforms as possible
> including DOS/Windows, hpux, FreeBSD and IRIX.  

Yes, MD5, double-crypt with pg_shadow salt and random salt.  Sounds like
a winner all around.

And finally, we need a trigger to somehow update non-md5 strings in the
pg_shadow password field.  No one is sure how to do that yet.

--  Bruce Momjian                        |  http://www.op.net/~candle pgman@candle.pha.pa.us               |  (610)
853-3000+  If your life is a hard drive,     |  830 Blythe Avenue +  Christ can be your backup.        |  Drexel Hill,
Pennsylvania19026
 


pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: You're on SecurityFocus.com for the cleartext passwords.
Next
From: The Hermit Hacker
Date:
Subject: Re: So we're in agreement....