Re: [ADMIN] Passwords in clear text in server log

Поиск
Список
Период
Сортировка
От Don Seiler
Тема Re: [ADMIN] Passwords in clear text in server log
Дата
Msg-id CAHJZqBBrUd68_Tj_NrPMRh4veF4oZU_T+8Aq2TCKQ=56aWeU7w@mail.gmail.com
обсуждение исходный текст
Ответ на Re: [ADMIN] Passwords in clear text in server log  (Scott Marlowe <scott.marlowe@gmail.com>)
Список pgsql-admin
On Wed, Oct 11, 2017 at 10:33 AM, Scott Marlowe <scott.marlowe@gmail.com> wrote:
FYI our standard hack here is to run

set log_statement='none';
alter user ...


I've seen that suggested in some forums as well. Then you aren't logging the fact that the password was changed at all. I think you'd still want to know of the fact that it occurred, but my suggestion is that we shouldn't be logging the value.

--
Don Seiler
www.seiler.us

В списке pgsql-admin по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: [ADMIN] Passwords in clear text in server log
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: [ADMIN] Passwords in clear text in server log