Re: crypt auth

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: crypt auth
Дата
Msg-id 48FC923A.5080402@gmx.net
обсуждение исходный текст
Ответ на crypt auth  (Magnus Hagander <magnus@hagander.net>)
Ответы Re: crypt auth  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Magnus Hagander wrote:
> I notice our docs have:
> 
>     If you are at all concerned about password
>     <quote>sniffing</> attacks then <literal>md5</> is preferred, with
>     <literal>crypt</> to be used only if you must support pre-7.2
>     clients. Plain <literal>password</> should be avoided especially for
> 
> 
> At what point do we just remove the support and say that people need to
> upgrade their clients? Sure, it's up to ppl not to configure it that
> way, but security-wise it's a foot-gun that I think is completely
> unnecessary.

AFAICT, removing an authentication method requires a protocol version 
bump.  If you think it is worth dealing with those complications, then 
go for it.  I think it might be worth it.


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Simon Riggs
Дата:
Сообщение: Re: Block level concurrency during recovery
Следующее
От: "Hitoshi Harada"
Дата:
Сообщение: Re: Window Functions: buffering strategy