Re: Successor of MD5 authentication, let's use SCRAM

Поиск
Список
Период
Сортировка
От Josh Berkus
Тема Re: Successor of MD5 authentication, let's use SCRAM
Дата
Msg-id 5078A0B1.8030401@agliodbs.com
обсуждение исходный текст
Ответ на Re: Successor of MD5 authentication, let's use SCRAM  (Stephen Frost <sfrost@snowman.net>)
Ответы Re: Successor of MD5 authentication, let's use SCRAM
Список pgsql-hackers
On 10/12/12 12:44 PM, Stephen Frost wrote:
> Don't get me wrong- I really dislike that
> we don't have something better today for people who insist on password
> based auth, but perhaps we should be pushing harder for people to use
> SSL instead?

Problem is, the fact that setting up SSL correctly is hard is outside of
our control.

Unless we can give people a "run these three commands on each server and
you're now SSL authenticating" script, we can continue to expect the
majority of users not to use SSL.  And I don't think that level of
simplicity is even theoretically possible.

-- 
Josh Berkus
PostgreSQL Experts Inc.
http://pgexperts.com



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Josh Berkus
Дата:
Сообщение: Re: Truncate if exists
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: Successor of MD5 authentication, let's use SCRAM