Re: Client-side password encryption - Mailing list pgadmin-hackers

From Dave Page
Subject Re: Client-side password encryption
Date
Msg-id E7F85A1B5FF8D44C8A1AF6885BC9A0E4850814@ratbert.vale-housing.co.uk
Whole thread Raw
In response to Client-side password encryption  (Peter Eisentraut <peter_e@gmx.net>)
Responses Re: Client-side password encryption
List pgadmin-hackers


-----Original Message-----
From: pgadmin-hackers-owner@postgresql.org on behalf of Peter Eisentraut
Sent: Sun 12/18/2005 2:25 AM
To: pgadmin-hackers@postgresql.org
Subject: [pgadmin-hackers] Client-side password encryption

> Commands like CREATE USER foo PASSWORD 'bar' transmit the password in
> cleartext and possibly save the password in various client or server
> log files.  I have just fixed this for psql and createuser to encrypt
> the password on the client side.  A quick check of the pgadmin3 source
> code shows that you are also affected by this issue.  I ask you to
> check where you paste cleartext passwords into SQL commands and change
> those to encrypt the password before sending or storing it anywhere.
> The required function pg_md5_encrypt() is contained in libpq.

So did you just rip it from there into psql? I don't see it in the list of libpq exports so if thats not the case, on
Windowsat least we'll need to change the api, and possibly the dll name as well to avoid any compatibility issues. 

Regards, Dave.

pgadmin-hackers by date:

Previous
From: Peter Eisentraut
Date:
Subject: Client-side password encryption
Next
From: Andreas Pflug
Date:
Subject: Re: Client-side password encryption