Re: SET SESSION AUTHORIZATION superuser limitation.

Поиск
Список
Период
Сортировка
От Dmitry Igrishin
Тема Re: SET SESSION AUTHORIZATION superuser limitation.
Дата
Msg-id CAAfz9KP1_7yTH9Ojeu0hfE2BqYZ7QtY2bnvfjt1Gc3ctUaqroQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: SET SESSION AUTHORIZATION superuser limitation.  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers


2015-12-21 17:57 GMT+03:00 Tom Lane <tgl@sss.pgh.pa.us>:
Robert Haas <robertmhaas@gmail.com> writes:
> On Sun, Dec 20, 2015 at 1:47 PM, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>> The syntax you propose exposes the user's password in cleartext in
>> the command, where it is likely to get captured in logs for example.
>> That's not going to do.

> Of course, right now, the ALTER USER ... PASSWORD command has that
> problem which is, uh, bad.

Which is why we invented the ENCRYPTED PASSWORD syntax, as well as
psql's \password command ... but using that approach for actual
login to an account would be a security fail as well.
The connection should be secured somehow (SSL/SSH...) to prevent password
thefts. On the other hand, the logging system should not log details of commands
like ALTER USER ...

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Viktor Leis
Дата:
Сообщение: Re: Experimental evaluation of PostgreSQL's query optimizer
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: Additional role attributes && superuser review