Re: Security with V9.3.3 standby servers - Mailing list pgsql-admin

From Albe Laurenz
Subject Re: Security with V9.3.3 standby servers
Date
Msg-id A737B7A37273E048B164557ADEF4A58B365A0E16@ntex2010i.host.magwien.gv.at
Whole thread Raw
In response to Security with V9.3.3 standby servers  (John Scalia <jayknowsunix@gmail.com>)
List pgsql-admin
John Scalia wrote:
> An edict has been handed down here from on high that no script shall ever contain any password in
> cleartext for any reason. Well this is problem with a streaming replication
> standby server's recovery.conf file as the line primary_conninfo = contains said replication user's
> password for that connection. Is there any sort of plan to allow this to be md5
> or some such encoded? Or what else could I do in this case?

Well, I would consider "trust" authentication.

If you restrict it to a single IP address, I don't think it is less secure
than having your password lying around on another computer.

Yours,
Laurenz Albe

pgsql-admin by date:

Previous
From: David G Johnston
Date:
Subject: Re: How to execute cursor in PostgreSQL?
Next
From: Josef Springer
Date:
Subject: Installing PostgreSQL fails