Re: Password complexity/history - credcheck?
От
Martin Goodson
Тема
Re: Password complexity/history - credcheck?
Дата
Msg-id
de507f6d-2c3b-4f35-9eda-99b81e2a1083@googlemail.com
Ответ на
Re: Password complexity/history - credcheck? (Christoph Moench-Tegeder)
Список
Дерево обсуждения
Password complexity/history - credcheck? Martin Goodson <kaemaril@googlemail.com>
Re: Password complexity/history - credcheck? Tom Lane <tgl@sss.pgh.pa.us>
Re: Password complexity/history - credcheck? Martin Goodson <kaemaril@googlemail.com>
Re: Password complexity/history - credcheck? Greg Sabino Mullane <htamfids@gmail.com>
2FA - - - was Re: Password complexity/history - credcheck? o1bigtenor <o1bigtenor@gmail.com>
Re: 2FA - - - was Re: Password complexity/history - credcheck? Chris Travers <chris.travers@gmail.com>
Re: Password complexity/history - credcheck? Christoph Moench-Tegeder <cmt@burggraben.net>
Re: Password complexity/history - credcheck? Martin Goodson <kaemaril@googlemail.com>
Re: Password complexity/history - credcheck? Laurenz Albe <laurenz.albe@cybertec.at>
Re: Password complexity/history - credcheck? Christoph Moench-Tegeder <cmt@burggraben.net>
Re: Password complexity/history - credcheck? Ron Johnson <ronljohnsonjr@gmail.com>
On 23/06/2024 11:49, Christoph Moench-Tegeder wrote:
My advice would be to not use secrets stored in the database - that is, do not use scram-sha-256 - but use an external authentication system, like Kerberos (might be AD) or LDAP (might also be AD) and have that managed by the security team: that way all these compliance
Crikey, that would be quite a lot of lot of SSL/TLS to set up. We have quite a few (massive understatement :( ... ) PostgreSQL database clusters spread over quite a lot (another understatement) of VMs.
The last time I suggested LDAP there was a lot of enthusiasm ... until they went down and looked at what might have to be done, after which it all became very quiet ...
Regards,
Martin.
В списке pgsql-general по дате отправления