Re: Encrypting pg_shadow passwords - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Encrypting pg_shadow passwords
Date
Msg-id 25154.992628150@sss.pgh.pa.us
Whole thread Raw
In response to Re: Encrypting pg_shadow passwords  (Vince Vielhaber <vev@michvhf.com>)
Responses Re: Encrypting pg_shadow passwords  (Vince Vielhaber <vev@michvhf.com>)
Re: Encrypting pg_shadow passwords  (Lincoln Yeoh <lyeoh@pop.jaring.my>)
List pgsql-hackers
Vince Vielhaber <vev@michvhf.com> writes:
>> More to the point, how does the postmaster know that it's now dealing
>> with encrypted passwords and must use the double-salt auth method?

> The first three characters are md5 in the code I sent Bruce.

Uh ... so if I use a password that starts with "md5", it breaks?

Seems like adding an additional column to pg_shadow would be a better
technique.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Peter Eisentraut
Date:
Subject: Re: Protocol Documentation
Next
From: Vince Vielhaber
Date:
Subject: Re: Encrypting pg_shadow passwords