Re: Re: Encrypting pg_shadow passwords

Поиск
Список
Период
Сортировка
От Frank Ch. Eigler
Тема Re: Re: Encrypting pg_shadow passwords
Дата
Msg-id 20010627124109.E7873@redhat.com
обсуждение исходный текст
Ответ на Re: Re: Encrypting pg_shadow passwords  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Hi -

tgl wrote:
: > Oh, I see finally.  You already put a custom little
: > challenge/response authentication scheme into postgresql,
: [...]
: Long before any of the current generation of developers, AFAIK.

Okay.  (Sorry about misinferring "You" above!)


: In any case, as several people have pointed out, one may well want to
: guard one's password more carefully than one guards the entire session
: contents.  Running SSL on a session that may transfer many megabytes
: is a lot of overhead.

Sure, but that's a separate performance question that shouldn't affect
the logical layering of the mechanisms.  With SSL, for example, methinks
it's possible to renegotiate a connection to turn off encryption after
a certain point.


- FChE

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Re: 7.2 items
Следующее
От: Tom Lane
Дата:
Сообщение: pg_largeobject is a security hole