Re: worried about PGPASSWORD drop

From: Alvaro Herrera <alvherre(at)atentus(dot)com>
To: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Christoph Dalitz <christoph(dot)dalitz(at)hs-niederrhein(dot)de>, PG Mailing List <pgsql-general(at)postgresql(dot)org>
Subject: Re: worried about PGPASSWORD drop
Date: 2002-08-28 16:02:22
Message-ID: Pine.LNX.4.44.0208281201560.2175-100000@cm-lcon1-46-187.cm.vtr.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-patches

Bruce Momjian dijo:

> Tom Lane wrote:

> > If you want to put in security restrictions that are actually useful,
> > where is the code to verify that PGPASSWORDFILE points at a
> > non-world-readable file? That needs to be there now, not later, or
> > we'll have people moaning about backward compatibility when we finally
> > do plug that hole.
>
> Agreed.

Point taken, will look into it later.

--
Alvaro Herrera (<alvherre[a]atentus.com>)
"La realidad se compone de muchos sueños, todos ellos diferentes,
pero en cierto aspecto, parecidos..." (Yo, hablando de sueños eróticos)

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message scott.marlowe 2002-08-28 16:02:59 Re: Performance Tuning / RAM Usage
Previous Message Oliver Elphick 2002-08-28 15:23:23 Re: Performance Tuning / RAM Usage

Browse pgsql-patches by date

  From Date Subject
Next Message Bruno Wolff III 2002-08-28 17:16:13 contrib/cube patches
Previous Message Dennis Bjorklund 2002-08-28 15:40:37 make life easier for translators