Re: password is no required, authentication is overridden - Mailing list pgsql-hackers

From Thomas Bley
Subject Re: password is no required, authentication is overridden
Date
Msg-id 44BD58A4.5090702@gmail.com
Whole thread Raw
In response to Re: password is no required, authentication is overridden  (Andrew Dunstan <andrew@dunslane.net>)
List pgsql-hackers
or maybe split the file up into sections like this example:

[pgadmin3]
localhost:5432:*:postgres:post

[pg_dump]

[psql]


bye
Thomas


Andrew Dunstan wrote:
> Thomas Bley wrote:
>
>>
>>
>> + The .pgpass file will be automatically created if you're using 
>> pgAdmin III with "store password" being enabled in the connection 
>> settings.
>>
>
> It strikes me that this is actually a bad thing for pgadmin3 to be 
> doing. It should use its own file, not the deafult location, at least 
> if the libpq version is >= 8.1. We provided the PGPASSFILE environment 
> setting just so programs like this could use alternative locations for 
> the pgpass file. Otherwise, it seems to me we are violating the POLS, 
> as in the case of this user who not unnaturally thought he had found a 
> major security hole.
>
> cheers
>
> andrew
>



pgsql-hackers by date:

Previous
From: Andrew Dunstan
Date:
Subject: Re: password is no required, authentication is overridden
Next
From: "Andrew Hammond"
Date:
Subject: Re: using constraint based paritioning to fix EAV