Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)

Поиск
Список
Период
Сортировка
От Robson Paniago de Miranda
Тема Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)
Дата
Msg-id 34ECA1DA.74B2@mpdft.gov.br
обсуждение исходный текст
Ответ на AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)  (Zeugswetter Andreas SARZ <Andreas.Zeugswetter@telecom.at>)
Список pgsql-hackers
Bruce Momjian wrote:
>
> > > But it is not secure.  Why have passwords then?
> > >
> >       I think is better have the encrypted passwords and the salt in pg_user.
> > I don't know if this will be bing a security hole :(
> >
>
> If we do this, then what does the frontend pass us?
>
> --
> Bruce Momjian
> maillist@candle.pha.pa.us

    I was thinking in the backend pass the salt stored in pg_user to the
frontend, but doing that is (almost) the same as having the password
stored in clear text. It was a bad idea :(

    Robson.

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)
Следующее
От: Frank Ridderbusch
Дата:
Сообщение: [HACKERS] Platform status