Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sKUIO-00AVtb-JT for pgsql-admin@arkaria.postgresql.org; Fri, 21 Jun 2024 02:46:36 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sKUIM-006mp1-UP for pgsql-admin@arkaria.postgresql.org; Fri, 21 Jun 2024 02:46:35 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sKUIM-006mml-9I for pgsql-admin@lists.postgresql.org; Fri, 21 Jun 2024 02:46:34 +0000 Received: from momjian.us ([72.94.173.45]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sKUIJ-002Lmk-Sf for pgsql-admin@lists.postgresql.org; Fri, 21 Jun 2024 02:46:33 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=momjian.us; s=2024011501; h=In-Reply-To:Content-Transfer-Encoding:Content-Type: MIME-Version:References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-ID:Content-Description; bh=I6ZL930OlGFA0RdnDwxXGujyDDQ8fXUbDrav7yr74UQ=; b=G1WCB9XtSgb6i6IP9NHfce1eLL PMLRCQdP5g0huPZM4ThjaUHood8QYuOYYr/sG9joqcAbCFkueSrh8IGZ/MFo1lIZ+qE0cz+mByLhk 22lS0E0m+guw8CRNZGMw6WDx+paAWDS78AY8SamIOayjX1WHCGYdIWs++PXHRIUVvMtRN0o/MESD4 HSZLfN8bpMqBZBEwePBNFEJqgB87w48dYEs/2ierXGI1Szvf8iRY7oW7r7pqz3Bn93HiB8qxiuFKL 8GLfHz6NzJp6+6tGEPulg2BHZ+nH1iA5zBlaYdAxPgpx2TJvsoJW1HGaLuaMEBVNOm8IPHdEyPW92 SeCvF5gw==; Received: from bruce by momjian.us with local (Exim 4.96) (envelope-from ) id 1sKUII-0013HB-1A; Thu, 20 Jun 2024 22:46:30 -0400 Date: Thu, 20 Jun 2024 22:46:30 -0400 From: Bruce Momjian To: Rui DeSousa Cc: Kashif Zeeshan , James Pang , pgsql-admin@lists.postgresql.org Subject: Re: password_rollover_time like Oracle Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, Jun 20, 2024 at 08:53:02PM -0400, Rui DeSousa wrote: > It can be achieved by using roles and rolling accounts. Then the application > would need to update username/password before it expires to the new account/ > password. The only difference is rather than changing just the password the > account information also changes; however, no permissions are ever given > directly to the user account. I’ve been in an environments that have use this > approach — Just remember to create the new user and update the username/ > password before they expire. > > i.e. > > approle (A role with no login and all the application permissions) > > create user appuser202406 with inherit in role approle valid until '07/01/2024' > encrypted password 'xxxx’; > create user appuser202407 with inherit in role approle valid until '08/01/2024' > encrypted password ‘yyyy'; I can see that causing problems if you want to store CURRENT_USER in the database, perhaps for auditing. I guess you could call it user4_login12 and keep incrementing the login number, but that seems cumbersome. -- Bruce Momjian https://momjian.us EDB https://enterprisedb.com Only you can decide what is important to you.