Re: Password settings requirements

Поиск
Список
Период
Сортировка
От Agil Azimov
Тема Re: Password settings requirements
Дата
Msg-id CAEQStSu8v2C8sJcMxk_h=9Kq=Ano0T8kXg6a0L9iOZ8UTVpwBQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Password settings requirements  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Password settings requirements  (Bruce Momjian <bruce@momjian.us>)
Список pgsql-novice
Thank you for your message. Will I be able to set all the settings I mentioned before if I will set SCRAM?

On Tue, 12 Oct 2021, 7:53 pm Tom Lane, <tgl@sss.pgh.pa.us> wrote:
Agil Azimov <agil.azimov@gmail.com> writes:
> Need to check the password settings in postgre such as Password minimal
> length, password complexity, password maximal age, password history and
> account lockout threshold.
> I need to set these parameters to make the comply with the best practices

If you're intent on doing things that way, you can set up Postgres
to use PAM authentication, and then the PAM end of things can be
configured with all kinds of options like that.

Personally though, I'd push back on those requirements.  The fundamental
problem with doing anything like that is that you cannot check password
length, complexity, etc without users having to send their cleartext
passwords to the server, which is a much bigger security fail than
anything appearing on your list.  Best practice these days is to use
SCRAM, which never exposes the cleartext password to the server.

                        regards, tom lane

В списке pgsql-novice по дате отправления:

Предыдущее
От: Agil Azimov
Дата:
Сообщение: Re: Password settings requirements
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: Password settings requirements