Re: Storing passwords

From: Andrew Rawnsley <ronz(at)ravensfield(dot)com>
To: Oleg Lebedev <oleg(dot)lebedev(at)waterford(dot)org>
Cc: Peter Eisentraut <peter_e(at)gmx(dot)net>, "pgsql-general(at)postgresql(dot)org" <pgsql-general(at)postgresql(dot)org>
Subject: Re: Storing passwords
Date: 2003-12-04 20:44:29
Message-ID: A831B16A-269A-11D8-90E3-000393A47FCC@ravensfield.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general


You can create MD5 or SHA-1 digests with java.security.MessageDigest.
They would
be stored as text

On Dec 1, 2003, at 4:01 PM, Oleg Lebedev wrote:

>
> Can Postgres JDBC driver encrypt a password before sending and
> inserting
> it into the password column?
>
> -----Original Message-----
> From: Peter Eisentraut [mailto:peter_e(at)gmx(dot)net]
> Sent: Monday, December 01, 2003 1:32 PM
> To: Oleg Lebedev
> Cc: pgsql-general(at)postgresql(dot)org
> Subject: Re: [GENERAL] Storing passwords
>
>
> Oleg Lebedev writes:
>
>> My application needs to store user names and passwords in the database
>
>> via JDBC connection. What is the right way to do this?
>
> One table, one column for the name, one column for the password.
>
>> What should be the database type of the password column?
>
> text or bytea, depending on how you encrypt it.
>
>> How do I encrypt the password before sending it to the database?
>
> Check out contrib/pgcrypto.
>
>> What other database settings need to be enabled for this to work?
>
> None.
>
> --
> Peter Eisentraut peter_e(at)gmx(dot)net
>
> *************************************
>
> This e-mail may contain privileged or confidential material intended
> for the named recipient only.
> If you are not the named recipient, delete this message and all
> attachments.
> Unauthorized reviewing, copying, printing, disclosing, or otherwise
> using information in this e-mail is prohibited.
> We reserve the right to monitor e-mail sent through our network.
>
> *************************************
>
>
> ---------------------------(end of
> broadcast)---------------------------
> TIP 9: the planner will ignore your desire to choose an index scan if
> your
> joining column's datatypes do not match
>
--------------------

Andrew Rawnsley
President
The Ravensfield Digital Resource Group, Ltd.
(740) 587-0114
www.ravensfield.com

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Alvar Freude 2003-12-04 20:47:01 Re: postgresql locks the whole table!
Previous Message Jan Wieck 2003-12-04 20:43:08 Re: query and pg_dump problem on my postgresql 6.5.3/Redhat