From: vrms <vrms@netcologne.de>
To: pgsql-admin@lists.postgresql.org
Subject: Re: Guidance on user deletion
Date: Sun, 12 May 2024 12:56:33 +0200
Message-ID: <7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de> (raw)
In-Reply-To: <CANzqJaA3d-QADYBWWA7uP9=LsbkC8+4uM3MHoZOCFHnpLwz=6Q@mail.gmail.com>
References: <f77fac58f3094867b9edc9a10904008f@evernorth.com>
<CANzqJaA3d-QADYBWWA7uP9=LsbkC8+4uM3MHoZOCFHnpLwz=6Q@mail.gmail.com>
> The five account systems I've had experience with (OpenVMS, Linux,
> Active Directory, SQL Server, Postgresql) all have the ability to
> expire users, and to unexpire them if the person ever returns.
how do you practically expire an account in postgres?
On 5/11/24 5:55 AM, Ron Johnson wrote:
> On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR)
> <Matthew.Wetmore@evernorth.com> wrote:
>
> Corporate env.
>
> I’ve searched for an official BestPractice on user deletion
> (leave company), but can’t find anything that is official-ish.
>
> Two options:
>
> 1. Change user psswd to nonsense, then expire account.
> 2. DROP user.
>
> There are +/- to both.
>
> I prefer #1, as it gives the exact timestamp of expire (protects
> company and ex-employee), but corporate auditors disagree.
>
> What do you do? Any official guidance on this?
>
>
> The five account systems I've had experience with (OpenVMS, Linux,
> Active Directory, SQL Server, Postgresql) all have the ability to
> expire users, and to unexpire them if the person ever returns. (That
> happened to me; my AD account was still there; they just reactivated
> it...)
> In *every* audit that I've gone through (and I go through them *every
> year* because of PCI) the auditors are perfectly happy to see that
> accounts are disabled. Occasionally they ask to see the log entry
> generated when one tries to log into Postgresql with an expired account.
>
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-admin@postgresql.org
Cc: vrms@netcologne.de, pgsql-admin@lists.postgresql.org
Subject: Re: Guidance on user deletion
In-Reply-To: <7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox