Client-side password encryption

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Client-side password encryption
Дата
Msg-id 200512180325.24912.peter_e@gmx.net
обсуждение исходный текст
Ответы Re: Client-side password encryption  (Peter Eisentraut <peter_e@gmx.net>)
Список pgadmin-hackers
Commands like CREATE USER foo PASSWORD 'bar' transmit the password in
cleartext and possibly save the password in various client or server
log files.  I have just fixed this for psql and createuser to encrypt
the password on the client side.  A quick check of the pgadmin3 source
code shows that you are also affected by this issue.  I ask you to
check where you paste cleartext passwords into SQL commands and change
those to encrypt the password before sending or storing it anywhere.
The required function pg_md5_encrypt() is contained in libpq.

--
Peter Eisentraut
http://developer.postgresql.org/~petere/

В списке pgadmin-hackers по дате отправления:

Предыдущее
От: Dave Page
Дата:
Сообщение: Re: [pgadmin-support] PgAdmin3 1.4.1 on Mac OSX 1.4.1 is
Следующее
От: "Dave Page"
Дата:
Сообщение: Re: Client-side password encryption