pg.ddx.io  pgsql-admin@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Rui DeSousa <rui.desousa@icloud.com>
To: Bruce Momjian <bruce@momjian.us>
Cc: Kashif Zeeshan <kashi.zeeshan@gmail.com>
Cc: James Pang <jamespang886@gmail.com>
Cc: pgsql-admin@lists.postgresql.org
Subject: Re: password_rollover_time like Oracle
Date: Thu, 20 Jun 2024 23:13:16 -0400
Message-ID: <15238DA9-4334-4838-9729-0B32CD83509F@icloud.com> (raw)
In-Reply-To: <ZnTphvVUrhiWipFp@momjian.us>
References: <CAHgTRff_h6d_dzQ4dNx+=Qs-misrSsHUNXzZYH+QGK193vJesw@mail.gmail.com>
	<CAAPsdheJ=7pwq0+GK1hiiLzeEzzp4dH1rK5doqqM8+EF_1jYZA@mail.gmail.com>
	<A359265B-7271-4C12-9CBB-37BDE6814EB2@icloud.com>
	<ZnTphvVUrhiWipFp@momjian.us>



> On Jun 20, 2024, at 10:46 PM, Bruce Momjian <bruce@momjian.us> wrote:
> 
> I can see that causing problems if you want to store CURRENT_USER in the
> database, perhaps for auditing.  I guess you could call it user4_login12
> and keep incrementing the login number, but that seems cumbersome.
> 
> -- 
>  Bruce Momjian  <bruce@momjian.us <mailto:bruce@momjian.us>>        https://momjian.us <https://momjian.us/;
>  EDB                                      https://enterprisedb.com <https://enterprisedb.com/;
> 
>  Only you can decide what is important to you.

I don’t think it’s too much of an issue for auditing as it’s same name with an embedded date code; however, I do think that changing a password every other month is cumbersome busy work and there are better ways to secure the account.  The problem I’ve seen with this type of solution is the application owners would commonly forget to update password information and then the application would stop working causing a scramble to update the credentials.  Then there is the account management itself, dropping expired users and creating new users for the upcoming month.  =

view thread (5+ messages)

Message-ID: <15238DA9-4334-4838-9729-0B32CD83509F@icloud.com>
Permalink:  ../15238DA9-4334-4838-9729-0B32CD83509F@icloud.com/
Also on:    postgresql.org/message-id/15238DA9-4334-4838-9729-0B32CD83509F@icloud.com

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: rui.desousa@icloud.com, bruce@momjian.us, kashi.zeeshan@gmail.com, jamespang886@gmail.com, pgsql-admin@lists.postgresql.org
  Subject: Re: password_rollover_time like Oracle
  In-Reply-To: <15238DA9-4334-4838-9729-0B32CD83509F@icloud.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox