password storage docs - Mailing list pgsql-docs

From Richard Hector
Subject password storage docs
Date
Msg-id 2da8edec-c930-bd42-1ba0-a8ed172c80f4@walnut.gen.nz
Whole thread Raw
Responses Re: password storage docs
List pgsql-docs
Hi,

Sending this as requested by xocolatl on #postgresql (irc).

On discovering that (md5) password hashes are stored in postgres in a
manner similar to this:

'md5' || md5('the most secret password' || 'username')

i.e. without the use of a random salt, it was suggested I should look
into the scram alternative.

I can't find information about the storage format for that at all -
other than "... and supports storing passwords on the server in a
cryptographically hashed form that is thought to be secure."

It would be nice to see more information on this.

Thanks,

Richard


pgsql-docs by date:

Previous
From: Thomas Munro
Date:
Subject: Re: typo in parallel safety doc
Next
From: Michael Paquier
Date:
Subject: Re: password storage docs