Re: PGPASSWORD and client tools - Mailing list pgsql-hackers

From Christopher Kings-Lynne
Subject Re: PGPASSWORD and client tools
Date
Msg-id 41240A8D.2040200@familyhealth.com.au
Whole thread Raw
In response to Re: PGPASSWORD and client tools  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: PGPASSWORD and client tools  (Andreas Pflug <pgadmin@pse-consulting.de>)
List pgsql-hackers
> It's deprecated because it's insecure, on platforms where other users can
> see the environment variables passed to pg_dump (which apparently is
> quite a few variants of Unix).  You wouldn't pass the password on the
> command line either ...
> 
> Painful as .pgpass may be for an admin tool, I do not know of any other
> method I'd recommend on a multiuser machine.

OK, but say you have a phpPgAdmin installation that's servicing 20 
users.  Then you have to put a .pgpass file in the www home dir (if 
there is one) with the usernames and passwords of all those users - 
pretty damn annoying...

Chris



pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: pg_dump 'die_on_errors'
Next
From: Tom Lane
Date:
Subject: More fun with dropped columns