Re: password security - Mailing list pgsql-general

From Bruce Momjian
Subject Re: password security
Date
Msg-id 200208212112.g7LLC0I06260@candle.pha.pa.us
Whole thread Raw
In response to password security  ("Johnson, Shaunn" <SJohnson6@bcbsm.com>)
List pgsql-general
Yes, have you set pg_hba.conf to MD5 for those hosts?

---------------------------------------------------------------------------

Johnson, Shaunn wrote:
> Howdy:
>
> Running PostgreSQL 7.2.1 on RedHat Linux 7.2.
>
> We have a user community that connects to the
> database via ODBC drivers.  They use a few
> applications, but for the most part, it's MS Access.
>
> I've changed the passwords for users so that
> they will have to set their passwords in
> the ODBC configuration.  On PostgreSQL I
> just did:
>
> "alter user <username> with encrypted 'passwd'"
>
> and it looked okay (no errors to speak of returned).
>
> BUT, when the users log on without changing thier
> configuration, they can still access the tables.
>
> Is there something else I should change?  Something
> in the hba.conf file?
>
> Any other documentation specifically to securing
> the database (permissions, groups, etc)?
>
> Thanks!
>
> -X

--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 359-1001
  +  If your life is a hard drive,     |  13 Roberts Road
  +  Christ can be your backup.        |  Newtown Square, Pennsylvania 19073

pgsql-general by date:

Previous
From: "Johnson, Shaunn"
Date:
Subject: password security
Next
From: rdkurth@starband.net
Date:
Subject: Can't get postgresql to work