pg.ddx.io  pgsql-admin@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: vrms <vrms@netcologne.de>
To: pgsql-admin@lists.postgresql.org
Subject: Re: Guidance on user deletion
Date: Sun, 12 May 2024 12:56:33 +0200
Message-ID: <7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de> (raw)
In-Reply-To: <CANzqJaA3d-QADYBWWA7uP9=LsbkC8+4uM3MHoZOCFHnpLwz=6Q@mail.gmail.com>
References: <f77fac58f3094867b9edc9a10904008f@evernorth.com>
	<CANzqJaA3d-QADYBWWA7uP9=LsbkC8+4uM3MHoZOCFHnpLwz=6Q@mail.gmail.com>


> The five account systems I've had experience with (OpenVMS, Linux, 
> Active Directory, SQL Server, Postgresql) all have the ability to 
> expire users, and to unexpire them if the person ever returns.
how do you practically expire an account in postgres?



On 5/11/24 5:55 AM, Ron Johnson wrote:
> On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR) 
> <Matthew.Wetmore@evernorth.com> wrote:
>
>     Corporate env.
>
>     I’ve searched for an official BestPractice on user  deletion
>     (leave company), but can’t find anything that is official-ish.
>
>     Two options:
>
>      1. Change user psswd to nonsense, then expire account.
>      2. DROP user.
>
>     There are +/- to both.
>
>     I prefer #1, as it gives the exact timestamp of expire (protects
>     company and ex-employee), but corporate auditors disagree.
>
>     What do you do?  Any official guidance on this?
>
>
> The five account systems I've had experience with (OpenVMS, Linux, 
> Active Directory, SQL Server, Postgresql) all have the ability to 
> expire users, and to unexpire them if the person ever returns.  (That 
> happened to me; my AD account was still there; they just reactivated 
> it...)
> In *every* audit that I've gone through (and I go through them *every 
> year* because of PCI) the auditors are perfectly happy to see that 
> accounts are disabled. Occasionally they ask to see the log entry 
> generated when one tries to log into Postgresql with an expired account.
>

view thread (6+ messages)  latest in thread

Message-ID: <7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de>
Permalink:  ../7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de/
Also on:    postgresql.org/message-id/7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: vrms@netcologne.de, pgsql-admin@lists.postgresql.org
  Subject: Re: Guidance on user deletion
  In-Reply-To: <7491004d-73f1-4c5f-aaaa-e397c0ba5c1b@netcologne.de>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox