Re: [HACKERS] SCRAM auth and Pgpool-II - Mailing list pgsql-hackers

From Chapman Flack
Subject Re: [HACKERS] SCRAM auth and Pgpool-II
Date
Msg-id 59681EF8.6060506@anastigmatix.net
Whole thread Raw
In response to Re: [HACKERS] SCRAM auth and Pgpool-II  (Tatsuo Ishii <ishii@sraoss.co.jp>)
Responses Re: [HACKERS] SCRAM auth and Pgpool-II
List pgsql-hackers
On 07/13/17 20:09, Tatsuo Ishii wrote:

> The comment in pg_hba.conf.sample seem to prefer md5 over clear text
> password.
> 
> # Note that "password" sends passwords in clear text; "md5" or
> # "scram-sha-256" are preferred since they send encrypted passwords.

Should that be reworded to eliminate "md5"? I'd consider "scram-sha-256"
suitable over a clear channel, but I've never recommended "md5" for that.

-Chap



pgsql-hackers by date:

Previous
From: Claudio Freire
Date:
Subject: Re: Fwd: [HACKERS] Vacuum: allow usage of more than 1GB of work mem
Next
From: Thomas Munro
Date:
Subject: Re: [HACKERS] Inadequate infrastructure for NextValueExpr