Re: MD5 authentication needs help

Поиск
Список
Период
Сортировка
От Jim Nasby
Тема Re: MD5 authentication needs help
Дата
Msg-id 54F8B7FD.8070706@BlueTreble.com
обсуждение исходный текст
Ответ на Re: MD5 authentication needs help  (Stephen Frost <sfrost@snowman.net>)
Ответы Re: MD5 authentication needs help  (Stephen Frost <sfrost@snowman.net>)
Re: MD5 authentication needs help  (Greg Stark <stark@mit.edu>)
Список pgsql-hackers
On 3/4/15 2:56 PM, Stephen Frost wrote:
>> 2)  The per-session salt sent to the client is only 32-bits, meaning
>> >that it is possible to reply an observed MD5 hash in ~16k connection
>> >attempts.
> Yes, and we have no (PG-based) mechanism to prevent those connection
> attempts, which is a pretty horrible situation to be in.

Is there some reason we don't just fix that? I'm thinking that this is a 
special case where we could just modify the pg_auth tuple in-place 
without bloating the catalog (we already do that somewhere else). Is 
there something else that makes this difficult? Are we afraid of an 
extra GUC to control it?
-- 
Jim Nasby, Data Architect, Blue Treble Consulting
Data in Trouble? Get it in Treble! http://BlueTreble.com



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Stephen Frost
Дата:
Сообщение: Re: deparsing utility commands
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: MD5 authentication needs help