password storage docs

Поиск
Список
Период
Сортировка
От Richard Hector
Тема password storage docs
Дата
Msg-id 2da8edec-c930-bd42-1ba0-a8ed172c80f4@walnut.gen.nz
обсуждение исходный текст
Ответы Re: password storage docs  (Michael Paquier <michael@paquier.xyz>)
Список pgsql-docs
Hi,

Sending this as requested by xocolatl on #postgresql (irc).

On discovering that (md5) password hashes are stored in postgres in a
manner similar to this:

'md5' || md5('the most secret password' || 'username')

i.e. without the use of a random salt, it was suggested I should look
into the scram alternative.

I can't find information about the storage format for that at all -
other than "... and supports storing passwords on the server in a
cryptographically hashed form that is thought to be secure."

It would be nice to see more information on this.

Thanks,

Richard


В списке pgsql-docs по дате отправления:

Предыдущее
От: Thomas Munro
Дата:
Сообщение: Re: typo in parallel safety doc
Следующее
От: Michael Paquier
Дата:
Сообщение: Re: password storage docs