Re: Differences in crypt hash? - Mailing list pgsql-docs

From Tom Lane
Subject Re: Differences in crypt hash?
Date
Msg-id 29263.996944702@sss.pgh.pa.us
Whole thread Raw
In response to Differences in crypt hash?  (Richard Hodges <rh@matriplex.com>)
Responses Re: Differences in crypt hash?  (Bruce Momjian <pgman@candle.pha.pa.us>)
List pgsql-docs
Richard Hodges <rh@matriplex.com> writes:
> The problem is that my Solaris client does not authenticate against
> my server (7.0.3 built on FreeBSD).

Indeed, one of the nasty things about the 'crypt' authentication method
is that it assumes the crypt() library call acts the same on both client
and server machine.  As you've just discovered, that ain't always so.

There have been plans for some time to supersede our present password
auth methods with something more secure and portable (probably MD5
double hashing at both ends).  I think Vince V. is working on that,
but I've not heard anything about it lately.  You can read all about it
in the pghackers mail archives if you care.

In the meantime, you'll just have to use a different auth method.
Plain "password" would work.  (If you're concerned about someone
sniffing your TCP connection, consider using SSL.)

            regards, tom lane

pgsql-docs by date:

Previous
From: Richard Hodges
Date:
Subject: Differences in crypt hash?
Next
From: Bruce Momjian
Date:
Subject: Re: Differences in crypt hash?