Re: prevent connection using pgpass.conf

From: John R Pierce <pierce(at)hogranch(dot)com>
To: pgsql-general(at)postgresql(dot)org
Subject: Re: prevent connection using pgpass.conf
Date: 2010-04-13 00:36:54
Message-ID: 4BC3BCA6.1090801@hogranch.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

Alban Hertroys wrote:
> I have to say I was a bit surprised to find that .pgpass files store those passwords as plain text though. Some method like ssh uses with public and private keys would be an improvement IMO. Especially since we can choose to use password encryption over the wire.
>
> Storing those passwords encrypted on the client side seems the proper way to deal with this issue. IMHO, time working on that is better spent than time trying to prevent .pgpass files from working.
>

afaik, the .pgpass file is something the user creates with his text
editor. if it was encrypted or hashed, there would need to be a
client side utility to create it.

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Bruce Momjian 2010-04-13 00:57:52 Re: Wikipedia entry - AmigaOS port - error?
Previous Message Bruce Momjian 2010-04-13 00:30:34 Re: prevent connection using pgpass.conf