Обсуждение: How to encrypt database password in pgpass or unix file to run batch jobs through shell script

Поиск
Список
Период
Сортировка

How to encrypt database password in pgpass or unix file to run batch jobs through shell script

От
aditya desai
Дата:
Hi,
We have Amazon RDS Postgres. Currently we are using .pgpass file and running psql from different EC2 instances to connect to DB. But the password in this file is not encrypted. What are our options to encrypt the password? Or do passwordless connection from EC2 to database? Lambda functions have limitations of running only for 15 minutes.

How can we setup different authentication methods for AWS RDS Postgres as we don't have access pg_hba.conf?

Regards,
Aditya. 

Re: How to encrypt database password in pgpass or unix file to run batch jobs through shell script

От
Bruce Momjian
Дата:
On Fri, Sep 25, 2020 at 03:04:56PM +0530, aditya desai wrote:
> Hi,
> We have Amazon RDS Postgres. Currently we are using .pgpass file and running
> psql from different EC2 instances to connect to DB. But the password in this
> file is not encrypted. What are our options to encrypt the password? Or do
> passwordless connection from EC2 to database? Lambda functions have limitations
> of running only for 15 minutes.
> 
> How can we setup different authentication methods for AWS RDS Postgres as we
> don't have access pg_hba.conf?

There is no encryption facility, though you can used the hashed value
rather than the literal password.  To encrypt, you would need to decrypt
it and then pass it to libpq, but there is no _pipe_ facility to do
that.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EnterpriseDB                             https://enterprisedb.com

  The usefulness of a cup is in its emptiness, Bruce Lee