Re: change password_encryption default to scram-sha-256?

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: change password_encryption default to scram-sha-256?
Дата
Msg-id 6774.1554701682@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: change password_encryption default to scram-sha-256?  (Michael Paquier <michael@paquier.xyz>)
Ответы Re: change password_encryption default to scram-sha-256?  (Andres Freund <andres@anarazel.de>)
Список pgsql-hackers
Michael Paquier <michael@paquier.xyz> writes:
> From what I can see, the major drivers not using directly libpq
> support our SASL protocol: JDBC and npgsql.  However I can count three
> of them which still don't support it: Crystal, pq (Go) and asyncpg.
> pq and asyncpg are very popular on github, with at least 3000 stars
> each, which is a lot I think.  I have also double-checked their source
> code and I am seeing no trace of SASL or SCRAM, so it seems to me that
> we may want to wait more before switching the default.

Perhaps we could reach out to the authors of those libraries,
and encourage them to provide support in the next year or so?

I don't doubt that switching to scram-sha-256 is a good idea in
the long run.  The idea here was to give driver authors a reasonable
amount of time to update.  I don't really think that one year
counts as a "reasonable amount of time" given how slowly this
project moves overall ... but we don't want to wait forever ...

            regards, tom lane



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Michael Paquier
Дата:
Сообщение: Re: change password_encryption default to scram-sha-256?
Следующее
От: Andres Freund
Дата:
Сообщение: Re: change password_encryption default to scram-sha-256?