agora inbox for pgsql-admin@postgresql.org
help / color / mirror / Atom feedFrom: Bruce Momjian <bruce@momjian.us>
To: Rui DeSousa <rui.desousa@icloud.com>
Cc: Kashif Zeeshan <kashi.zeeshan@gmail.com>
Cc: James Pang <jamespang886@gmail.com>
Cc: pgsql-admin@lists.postgresql.org
Subject: Re: password_rollover_time like Oracle
Date: Thu, 20 Jun 2024 22:46:30 -0400
Message-ID: <ZnTphvVUrhiWipFp@momjian.us> (raw)
In-Reply-To: <A359265B-7271-4C12-9CBB-37BDE6814EB2@icloud.com>
References: <CAHgTRff_h6d_dzQ4dNx+=Qs-misrSsHUNXzZYH+QGK193vJesw@mail.gmail.com>
<CAAPsdheJ=7pwq0+GK1hiiLzeEzzp4dH1rK5doqqM8+EF_1jYZA@mail.gmail.com>
<A359265B-7271-4C12-9CBB-37BDE6814EB2@icloud.com>
On Thu, Jun 20, 2024 at 08:53:02PM -0400, Rui DeSousa wrote:
> It can be achieved by using roles and rolling accounts. Then the application
> would need to update username/password before it expires to the new account/
> password. The only difference is rather than changing just the password the
> account information also changes; however, no permissions are ever given
> directly to the user account. I’ve been in an environments that have use this
> approach — Just remember to create the new user and update the username/
> password before they expire.
>
> i.e.
>
> approle (A role with no login and all the application permissions)
>
> create user appuser202406 with inherit in role approle valid until '07/01/2024'
> encrypted password 'xxxx’;
> create user appuser202407 with inherit in role approle valid until '08/01/2024'
> encrypted password ‘yyyy';
I can see that causing problems if you want to store CURRENT_USER in the
database, perhaps for auditing. I guess you could call it user4_login12
and keep incrementing the login number, but that seems cumbersome.
--
Bruce Momjian <bruce@momjian.us> https://momjian.us
EDB https://enterprisedb.com
Only you can decide what is important to you.
view thread (5+ messages) latest in thread
Message-ID: <ZnTphvVUrhiWipFp@momjian.us>
Permalink: ../ZnTphvVUrhiWipFp@momjian.us/
Also on: postgresql.org/message-id/ZnTphvVUrhiWipFp@momjian.us
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-admin@postgresql.org
Cc: bruce@momjian.us, rui.desousa@icloud.com, kashi.zeeshan@gmail.com, jamespang886@gmail.com, pgsql-admin@lists.postgresql.org
Subject: Re: password_rollover_time like Oracle
In-Reply-To: <ZnTphvVUrhiWipFp@momjian.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox