From: | Robert Haas <robertmhaas(at)gmail(dot)com> |
---|---|
To: | José Luis Tallón <jltallon(at)adv-solutions(dot)net> |
Cc: | Michael Paquier <michael(dot)paquier(at)gmail(dot)com>, Julian Markwort <julian(dot)markwort(at)uni-muenster(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, Stephen Frost <sfrost(at)snowman(dot)net>, David Steele <david(at)pgmasters(dot)net>, PostgreSQL mailing lists <pgsql-hackers(at)postgresql(dot)org>, Valery Popov <v(dot)popov(at)postgrespro(dot)ru> |
Subject: | Re: Password identifiers, protocol aging and SCRAM protocol |
Date: | 2016-03-30 20:34:24 |
Message-ID: | CA+TgmoZ=162kiqMV5pASU6_T1yTPAORrKxWgnWd7vr6BrxELaw@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
On Wed, Mar 30, 2016 at 12:31 PM, José Luis Tallón
<jltallon(at)adv-solutions(dot)net> wrote:
> On 03/30/2016 06:14 PM, Robert Haas wrote:
>> So basically the use of the ENCRYPTED keyword means "if it does already
>> seem to be the sort of MD5 blob we're expecting, turn it into that".
>
> If it does NOT already seem to be... I guess?
Yes, that's what I meant. Sorry.
>> rolencryption says how the password verifier is encrypted and rolpassword
>> contains the verifier itself. Initially, rolencryption will be 'plain' or
>> 'md5', but later we can add 'scram' as another choice, or maybe it'll be
>> more specific like 'scram-hmac-doodad'.
>
> May I suggest using "{" <scheme>["."<encoding>] "}" just like Dovecot does?
Doesn't seem very SQL-ish to me... I think we should normalize.
--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company
From | Date | Subject | |
---|---|---|---|
Next Message | Julien Rouhaud | 2016-03-30 21:09:33 | Re: Publish autovacuum informations |
Previous Message | Kevin Grittner | 2016-03-30 20:29:56 | Re: snapshot too old, configured by time |