Re: Modern SHA2- based password hashes for pgcrypto - Mailing list pgsql-hackers

From Daniel Gustafsson
Subject Re: Modern SHA2- based password hashes for pgcrypto
Date
Msg-id EB28D69B-3EA2-4A75-9ED0-7C8604941383@yesql.se
Whole thread Raw
Responses Re: Modern SHA2- based password hashes for pgcrypto
List pgsql-hackers
> On 31 Dec 2024, at 17:06, Bernd Helmle <mailings@oopsware.de> wrote:

> I adapted the code from the publicly available reference implementation
> at [1]. It's based on our existing OpenSSL infrastructure in pgcrypto
> and produces compatible password hashes with crypt() and "openssl
> passwd" with "-5" and "-6" switches.

Potentially daft question, but since we require OpenSSL to build pgcrypto, why
do we need to include sha2 code instead of using the sha2 implementation in
libcrypto? How complicated would it be to use the OpenSSL API instead?

--
Daniel Gustafsson




pgsql-hackers by date:

Previous
From: Andres Freund
Date:
Subject: Re: FileFallocate misbehaving on XFS
Next
From: Bernd Helmle
Date:
Subject: Re: Modern SHA2- based password hashes for pgcrypto