Re: Maximum password length - Mailing list pgsql-hackers

From Bossart, Nathan
Subject Re: Maximum password length
Date
Msg-id B507DFCA-B70E-450C-9CB2-D03881D45B60@amazon.com
Whole thread Raw
In response to Re: Maximum password length  (Stephen Frost <sfrost@snowman.net>)
Responses Re: Maximum password length
List pgsql-hackers
On 10/12/18, 4:24 PM, "Stephen Frost" <sfrost@snowman.net> wrote:
> * Bossart, Nathan (bossartn@amazon.com) wrote:
>> My main motivation for suggesting the increase to 8k is to provide
>> flexibility for alternative authentication methods like LDAP, RADIUS,
>> PAM, and BSD.
>
> Specific use-cases here would be better than hand-waving at "these other
> things."  Last I checked, all of those work with what we've got today
> and I don't recall hearing complaints about them not working due to this
> limit.

The main one I am thinking of is generated security tokens.  It seems
reasonable to me to limit md5 and scram-sha-256 passwords to a much
shorter length, but I think the actual server message limit should be
somewhat more flexible.

Nathan


pgsql-hackers by date:

Previous
From: Amit Langote
Date:
Subject: Re: Calculate total_table_pages after set_base_rel_sizes()
Next
From: Tom Lane
Date:
Subject: Re: [HACKERS] removing abstime, reltime, tinterval.c, spi/timetravel