Re: PGPASSWORD and client tools - Mailing list pgsql-hackers

From Andreas Pflug
Subject Re: PGPASSWORD and client tools
Date
Msg-id 41247ACC.1010605@pse-consulting.de
Whole thread Raw
In response to Re: PGPASSWORD and client tools  (Christopher Kings-Lynne <chriskl@familyhealth.com.au>)
List pgsql-hackers
Christopher Kings-Lynne wrote:
>> It's deprecated because it's insecure, on platforms where other users can
>> see the environment variables passed to pg_dump (which apparently is
>> quite a few variants of Unix).  You wouldn't pass the password on the
>> command line either ...
>>
>> Painful as .pgpass may be for an admin tool, I do not know of any other
>> method I'd recommend on a multiuser machine.
> 
> 
> OK, but say you have a phpPgAdmin installation that's servicing 20 
> users.  Then you have to put a .pgpass file in the www home dir (if 
> there is one) with the usernames and passwords of all those users - 
> pretty damn annoying...

Even worse, if you have a server registered more than once with 
different credentials...
I tried redirecting pg_dump's stdin but that locked up under win32.

Regards,
Andreas


pgsql-hackers by date:

Previous
From: Fabien COELHO
Date:
Subject: Re: tablespace and sequences?
Next
From: Fabien COELHO
Date:
Subject: Re: tablespace and sequences?