Re: add warning upon successful md5 password auth - Mailing list pgsql-hackers

From Tom Lane
Subject Re: add warning upon successful md5 password auth
Date
Msg-id 543884.1771004590@sss.pgh.pa.us
Whole thread Raw
In response to Re: add warning upon successful md5 password auth  (Nathan Bossart <nathandbossart@gmail.com>)
List pgsql-hackers
Nathan Bossart <nathandbossart@gmail.com> writes:
> On Fri, Feb 13, 2026 at 06:04:14AM +0100, Andreas Karlsson wrote:
>> The patch looks good and I think it would make sense to merge it in 19, why
>> wait for 20? But the main question I see is if this is too noisy or not.
>> Some applications connected to PostgreSQL quite a lot and I am sure we would
>> make some users unhappy so I am not fully on board with this patch. But on
>> the other hand we have way too many people who still use md5 and we really
>> should push them towards using scram.

> FWIW if users are really annoyed with these warnings, they can disable them
> by setting md5_password_warnings to off.  But I think we really ought to do
> something like $subject before we completely remove MD5 password support.

+1.  We need something like this to be there for at least a year or
two before we can consider removing MD5 passwords entirely.  As long
as the warnings can be turned off, I think it's all right and indeed
necessary to have them on-by-default.

            regards, tom lane

PS: I've not read the patch, so this isn't an endorsement of details.



pgsql-hackers by date:

Previous
From: Nathan Bossart
Date:
Subject: Re: add warning upon successful md5 password auth
Next
From: Tom Lane
Date:
Subject: Re: CREATE TABLE LIKE INCLUDING POLICIES