Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sir7p-00ADPm-6q for pgsql-admin@arkaria.postgresql.org; Tue, 27 Aug 2024 08:00:26 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sir7n-003T38-6l for pgsql-admin@arkaria.postgresql.org; Tue, 27 Aug 2024 08:00:23 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sir7m-003T2z-H1 for pgsql-admin@lists.postgresql.org; Tue, 27 Aug 2024 08:00:23 +0000 Received: from mailout3.izum.si ([193.2.126.3]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sir7j-001eXo-8x for pgsql-admin@lists.postgresql.org; Tue, 27 Aug 2024 08:00:21 +0000 Received: from EXSRV-01.izum.pri (EXSRV-01.izum.pri [10.1.100.193]) by mailout3.izum.si (Postfix) with ESMTPS id 04BDC60285F7 for ; Tue, 27 Aug 2024 10:00:16 +0200 (CEST) DKIM-Filter: OpenDKIM Filter v2.11.0 mailout3.izum.si 04BDC60285F7 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=izum.si; s=20210129; t=1724745616; bh=2HruPUXqxOQhPvKHRvbhzrklHmPn9ymK2TPyoIUyAFo=; h=From:To:Subject:Date:From; b=l6JZ7g1UHLKo83PkEZBFT3ceDe7hefROlMYm5Etzws6yazYRZk0ODJ/bUqzma2vPb aUuGbHVvDp7LbW801e6Q0yHQfprCPWfmfQ0H5NW0osIpWc6WkEohi2ftk1oQ0Vykj2 sXxGV9FuS0xV9+OSLyReX60UchReR/safdhA1ta2zrQg57nOY5AwwIyYDQwVPYcEkd FCqpjMvbXKxFpFnn9eyTJ3x3Fg4cf8c7J1kdA3qemLB6iYOc/LlDly4w7eb23dCXTg 1OW/cYRzfVx+kmU+8g+u9dMcqGDPuH0kbYSlDEHaYxfLJ+ggPliyGHmVKYmJ5U0uZb w5Hu3koQ6SDvQ== Received: from EXSRV-02.izum.pri (10.1.100.197) by EXSRV-01.izum.pri (10.1.100.193) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.34; Tue, 27 Aug 2024 10:00:15 +0200 Received: from EXSRV-02.izum.pri ([fe80::f170:99d6:d141:23e6]) by EXSRV-02.izum.pri ([fe80::f170:99d6:d141:23e6%8]) with mapi id 15.01.2507.034; Tue, 27 Aug 2024 10:00:15 +0200 From: =?iso-8859-2?Q?Domen_=A9etar?= To: "pgsql-admin@lists.postgresql.org" Subject: Unexpected authentication behaviour Thread-Topic: Unexpected authentication behaviour Thread-Index: Adr4Vc5cAencq2qqQ9CIxgoTYpAAcw== Date: Tue, 27 Aug 2024 08:00:15 +0000 Message-ID: Accept-Language: sl-SI, en-US Content-Language: en-US X-MS-Has-Attach: yes X-MS-TNEF-Correlator: x-originating-ip: [10.1.100.6] Content-Type: multipart/related; boundary="_004_cf9da30891024073938cdb23be9efaf5izumsi_"; type="multipart/alternative" MIME-Version: 1.0 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --_004_cf9da30891024073938cdb23be9efaf5izumsi_ Content-Type: multipart/alternative; boundary="_000_cf9da30891024073938cdb23be9efaf5izumsi_" --_000_cf9da30891024073938cdb23be9efaf5izumsi_ Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable Hi Admins, I have strange issue that I can't explain to myself: I want to use scram-sha-256 authentication on postgresql 16. Parameter password_encryption is set to scram-sha-256. I defined a user wit= h scram-sha-256 encoded password. My pg_hba.conf have following lines: # TYPE DATABASE USER ADDRESS METHOD local all all = peer host all all samenet = md5 Even though there is defined md5 authentication method for remote logins in= pg_hba.conf I can make remote login to my postgresql server which is unexp= ected behaviour of postgresql. What did I miss? Best regards! [izum] Domen =A9etar Computer Systems Support IZUM - Institute of Information Science | Pre=B9ernova ulica 17 | 2000 Mari= bor | Slovenia T: +386 2 25 20 339 | M: +386 41 676 342 | www.izum.si= | domen.setar@izum.si --_000_cf9da30891024073938cdb23be9efaf5izumsi_ Content-Type: text/html; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable

Hi Admins,

 

I have strange issu= e that I can't explain to myself:

 

I want to use scram= -sha-256 authentication on postgresql 16.

Parameter password_= encryption is set to scram-sha-256. I defined a user with scram-sha-256 enc= oded password.

My pg_hba.conf have=  following  lines:

 

# TYPE  DATABA= SE        USER    &n= bsp;       ADDRESS    &nb= sp;            METHO= D

local   &= nbsp;  all         &= nbsp;            &nb= sp;   all         &n= bsp;            = ;            &n= bsp;            &nbs= p;          peer

host  &nb= sp;    all        &n= bsp;            &nbs= p;    all        &nb= sp;          samenet &nbs= p;            &= nbsp;      md5

 

Even though there i= s defined md5 authentication method for remote logins in pg_hba.conf I can = make remote login to my postgresql server which is unexpected behaviour of = postgresql.

What did I miss?

 

Best regards!

3D"izum=

Domen =A9etar
Computer Systems Support
IZUM ̵= 1; Institute of Information Science | Pre=B9er= nova ulica 17 | 2000 Maribor | Slovenia
T: = 3;386 2 25 20 339 | M: += 386 41 676 342 | www.izum.si |
domen.setar@izum.si

 

 

--_000_cf9da30891024073938cdb23be9efaf5izumsi_-- --_004_cf9da30891024073938cdb23be9efaf5izumsi_ Content-Type: image/jpeg; name="image002.jpg" Content-Description: image002.jpg Content-Disposition: inline; filename="image002.jpg"; size=1318; creation-date="Tue, 27 Aug 2024 08:00:15 GMT"; modification-date="Tue, 27 Aug 2024 08:00:15 GMT" Content-ID: Content-Transfer-Encoding: base64 /9j/4AAQSkZJRgABAQEAYABgAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0a HBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwhMjIyMjIy MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjL/wAARCABHAEcDASIA AhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQA AAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3 ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWm p6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEA AwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSEx BhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElK U1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3 uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD3+iii gArN1OR0vdIVXZVe8ZXAONw8mU4P4gH8K0qwvE2q6ZoqaZfarctbwJeYVwpYbjFIOcc4xn8cVUU2 7ImTsrhqU0qaN4idZXVokk8tg2Cn7hTx6c81uD7o+lcFf+PfBsmmarF/bYb7Wj5VInLDMYTAyME8 frXer90fSnKLjuhRkm9GLRRRUFhRRRQAUUUUAFZev2Oj32lsuuR2z2UbCQm4ICoR0OT06n8zWpXJ +PNP07VLPSbTVGuBbPqAOLeMuxYQykAgAnHHPB/qLp/EiZ/Czj4brw1f6odK0bwvDr1swMc1zBYR QtDkdfMwqnrx936mvWx0rjfsNg2lyaZa6tqNlDLG0KD7KIUXcMDnylA6+oNdkOgqqruyKSsLRRRW RqFFFFABRRRQAVz3i7XZfD9pYXUOmy6g0l2IjDCu6QAxyElR6jb+Wa6Guc8Y3mtWVnp76FFDPeNd 4MMuMSIIpGKg9j8vXIq6avJJkVHaLOavfGer67ZT6VY+DtWjmvI2g827iMccYYbdzHHQZzivRYlZ YkVm3MFAJ9TXn8vjKDxFoGoJaXVzo2v2MDym0lO1wyrkjBGHHHpkegzXoQ+6PpV1VbS1iaevW4tF FFYmoUUUUAFFFFABXM+NLvTLG00y51S/ubCOO+UxXMAB2P5cn3gVbKkbh07iumrG1+ysNQfS7XUL NLqJ7w7UkAKhhDKckEHdxnj1IParhZS1Jnfl0OB8X6v8O/Etg8lxqii+ijJiuIImEuQOn3QDn0P6 V6sv3R9K4/UfDfhhdJ1iQ+HNPH2WJwfLgRWOIw3DbflPOM9sZrsB0FVUlFpKN/mRTi022LRRRWRq FFFFABRRRQAVmar/AMf+i/8AX63/AKImooprcUtilqv/ACA/E/8A1zk/9J1rfHQUUU3sJbi0UUVJ QUUUUAf/2Q== --_004_cf9da30891024073938cdb23be9efaf5izumsi_--