Re: Encrypting pg_shadow passwords - Mailing list pgsql-hackers

From Lincoln Yeoh
Subject Re: Encrypting pg_shadow passwords
Date
Msg-id 3.0.5.32.20010625140753.008449d0@192.228.128.13
Whole thread Raw
In response to Re: Encrypting pg_shadow passwords  (Bruce Momjian <pgman@candle.pha.pa.us>)
List pgsql-hackers
At 12:20 AM 26-06-2001 -0400, Bruce Momjian wrote:
>> 
>> at this point in time, i do not see a method of doing that without my mods
>> or using external password files.
>
>We will do double-crypt and everyone will be happy, right?

Wow optimistic :).

>> if the API as above existed, then i would be happy to see "password" go
away
>> (although it should be depreciated to a --enable option, otherwise you are
>> going to ruin a bunch of existing code).
>
>Who is using it?  We can continue to allow it but at some point there is
>no purpose to it unless you have clients that are pre-7.2.  Double-crypt
>removes the use for it, no?

I'm using "password".

If I feel that the wire isn't safe I'll use SSL.

Cheerio,
Link.



pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: Encrypting pg_shadow passwords
Next
From: Lincoln Yeoh
Date:
Subject: Re: Encrypting pg_shadow passwords