Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> writes:
> MD5(MD5(username+user_salt)+random_salt)
> Postmaster takes its pg_shadow MD5(username+user_salt) and does another
> MD5 with the random salt and compares it with what was sent from the
> client.
Doesn't seem quite right ... where's the password?
regards, tom lane