Re: worried about PGPASSWORD drop - Mailing list pgsql-general

From Bruce Momjian
Subject Re: worried about PGPASSWORD drop
Date
Msg-id 200208281354.g7SDsu413639@candle.pha.pa.us
Whole thread Raw
In response to Re: worried about PGPASSWORD drop  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: worried about PGPASSWORD drop  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-general
Tom Lane wrote:
> Christoph Dalitz <christoph.dalitz@hs-niederrhein.de> writes:
> > In the TODO list on http://developer.postgresql.org/todo.php,
> > I found the following entry:
> >  - Remove PGPASSWORD because it is insecure on some OS's, in 7.4
> > Why?
>
> I don't agree with removing the feature either, since it's perfectly
> useful on many OSes.  However your assumption:

The reason for the suggested removal is that we don't have a way of
knowing with OS's are secure, and which are not.  If we could determine
which OS's were secure, and enable it only on those, it would be OK to
keep it.


--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 359-1001
  +  If your life is a hard drive,     |  13 Roberts Road
  +  Christ can be your backup.        |  Newtown Square, Pennsylvania 19073

pgsql-general by date:

Previous
From: "Markus Wollny"
Date:
Subject: Naming-scheme for db-files
Next
From: Tom Lane
Date:
Subject: Re: worried about PGPASSWORD drop