Re: Can we stop defaulting to 'ident'?

From: Craig Ringer <craig(at)2ndquadrant(dot)com>
To: Christoph Berg <myon(at)debian(dot)org>, Stephen Frost <sfrost(at)snowman(dot)net>, Devrim Gündüz <devrim(at)gunduz(dot)org>, Craig Ringer <craig(at)2ndquadrant(dot)com>, pgsql-pkg-yum <pgsql-pkg-yum(at)postgresql(dot)org>
Subject: Re: Can we stop defaulting to 'ident'?
Date: 2019-12-23 06:06:18
Message-ID: CAMsr+YEEjv_e=eP0W=LRFAKEMtgEs0jaHUZ7V3BgvQzCKu62eA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-pkg-debian pgsql-pkg-yum

On Fri, 20 Dec 2019 at 23:15, Christoph Berg <myon(at)debian(dot)org> wrote:

> Re: Stephen Frost 2019-12-20 <20191220150644(dot)GO3195(at)tamriel(dot)snowman(dot)net>
> > SCRAM is *definitely* better and I strongly support us moving to it,
> > provided it doesn't break anything existing (which it generally
> > shouldn't... but maybe there's some weird edge cases, or possibly older
> > clients, but still, at some point, we need to move this default to be
> > SCRAM).
>
> TBH I haven't really read the manual section about md5-scram
> compatibility yet, but from memory, there's a lot of footnotes that
> need to be taken into account before the switch can be flipped, if
> upgrades from old servers are to be supported. The process sounds
> scary and painful.
>
>
Yeah. Everyone's already changing the setting after install or overriding
it at setup time anyway though, because 'ident' is so nonsensical hardly
anyone will be deploying with it.

We're not talking about changing the default from 'md5' to 'md5-scram'
which would be rather riskier.

And to be clear, I'm only proposing changing 'host' connections. 'local'
connections should remain 'peer' as is the case now.

--
Craig Ringer http://www.2ndQuadrant.com/
2ndQuadrant - PostgreSQL Solutions for the Enterprise

In response to

Browse pgsql-pkg-debian by date

  From Date Subject
Next Message Christoph Berg 2019-12-23 12:45:51 Re: Can we stop defaulting to 'ident'?
Previous Message Craig Ringer 2019-12-23 06:04:25 Re: Can we stop defaulting to 'ident'?

Browse pgsql-pkg-yum by date

  From Date Subject
Next Message Christoph Berg 2019-12-23 12:45:51 Re: Can we stop defaulting to 'ident'?
Previous Message Craig Ringer 2019-12-23 06:04:25 Re: Can we stop defaulting to 'ident'?