Re: password administration - Mailing list pgsql-admin

From Tom Lane
Subject Re: password administration
Date
Msg-id 29356.1281040367@sss.pgh.pa.us
Whole thread Raw
In response to password administration  ("Mark Steben" <msteben@autorevenue.com>)
Responses Re: password administration  (Victor Hugo <vh.clemente@gmail.com>)
List pgsql-admin
"Mark Steben" <msteben@autorevenue.com> writes:
> I would like to set up a facility that enforces password changes for roles
> After a predefined period (30 days for instance) when logging into psql
> Or, at the very least, send an email out to notify that your current
> Password period is about to expire.

Usually we suggest using PAM when you want to do this, as there's all
sorts of spare parts out there already for PAM-managed passwords.

(I concur with the response questioning whether forced password changes
are good policy, especially with an interval as short as that.  But if
you've got bullheaded management to deal with, PAM is the place to
look.)

            regards, tom lane

pgsql-admin by date:

Previous
From: Scott Marlowe
Date:
Subject: Re: password administration
Next
From: Scott Marlowe
Date:
Subject: Re: password administration