pg.ddx.io  pgsql-admin@postgresql.org mailing list archive  
help / color / mirror / Atom feed
Guidance on user deletion
6+ messages / 4 participants
[nested] [flat]

* Guidance on user deletion
@ 2024-05-10 15:13 Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
  2024-05-10 19:01 ` Re: Guidance on user deletion David G. Johnston <david.g.johnston@gmail.com>
  2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
  0 siblings, 2 replies; 6+ messages in thread

From: Wetmore, Matthew (CTR) @ 2024-05-10 15:13 UTC (permalink / raw)
  To: pgsql-admin@lists.postgresql.org <pgsql-admin@lists.postgresql.org>

Corporate env.

I've searched for an official BestPractice on user  deletion (leave company), but can't find anything that is official-ish.

Two options:


  1.  Change user psswd to nonsense, then expire account.
  2.  DROP user.

There are +/- to both.

I prefer #1, as it gives the exact timestamp of expire (protects company and ex-employee), but corporate auditors disagree.

What do you do?  Any official guidance on this?

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: Guidance on user deletion
  2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
@ 2024-05-10 19:01 ` David G. Johnston <david.g.johnston@gmail.com>
  1 sibling, 0 replies; 6+ messages in thread

From: David G. Johnston @ 2024-05-10 19:01 UTC (permalink / raw)
  To: Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>; +Cc: pgsql-admin@lists.postgresql.org

On Fri, May 10, 2024, 11:37 Wetmore, Matthew (CTR) <
Matthew.Wetmore@evernorth.com> wrote:

> Corporate env.
>
>
>
> I’ve searched for an official BestPractice on user  deletion (leave
> company), but can’t find anything that is official-ish.
>
>
>
> Two options:
>
>
>
>    1. Change user psswd to nonsense, then expire account.
>    2. DROP user.
>
>
>
> There are +/- to both.
>
>
>
> I prefer #1, as it gives the exact timestamp of expire (protects company
> and ex-employee), but corporate auditors disagree.
>
>
>
> What do you do?  Any official guidance on this?
>
>
>

Use proper off-machine audit logs to make the auditors happy then drop
stuff no longer has relevance.

David J.

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: Guidance on user deletion
  2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
@ 2024-05-11 03:55 ` Ron Johnson <ronljohnsonjr@gmail.com>
  2024-05-12 10:56   ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
  1 sibling, 1 reply; 6+ messages in thread

From: Ron Johnson @ 2024-05-11 03:55 UTC (permalink / raw)
  To: Pgsql-admin <pgsql-admin@lists.postgresql.org>

On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR) <
Matthew.Wetmore@evernorth.com> wrote:

> Corporate env.
>
>
>
> I’ve searched for an official BestPractice on user  deletion (leave
> company), but can’t find anything that is official-ish.
>
>
>
> Two options:
>
>
>
>    1. Change user psswd to nonsense, then expire account.
>    2. DROP user.
>
>
>
> There are +/- to both.
>
>
>
> I prefer #1, as it gives the exact timestamp of expire (protects company
> and ex-employee), but corporate auditors disagree.
>
>
>
> What do you do?  Any official guidance on this?
>

The five account systems I've had experience with (OpenVMS, Linux, Active
Directory, SQL Server, Postgresql) all have the ability to expire users,
and to unexpire them if the person ever returns.  (That happened to me; my
AD account was still there; they just reactivated it...)

In *every* audit that I've gone through (and I go through them *every
year* because
of PCI) the auditors are perfectly happy to see that accounts are
disabled.  Occasionally they ask to see the log entry generated when one
tries to log into Postgresql with an expired account.

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: Guidance on user deletion
  2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
  2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
@ 2024-05-12 10:56   ` vrms <vrms@netcologne.de>
  2024-05-12 13:20     ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: vrms @ 2024-05-12 10:56 UTC (permalink / raw)
  To: pgsql-admin@lists.postgresql.org


> The five account systems I've had experience with (OpenVMS, Linux, 
> Active Directory, SQL Server, Postgresql) all have the ability to 
> expire users, and to unexpire them if the person ever returns.
how do you practically expire an account in postgres?



On 5/11/24 5:55 AM, Ron Johnson wrote:
> On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR) 
> <Matthew.Wetmore@evernorth.com> wrote:
>
>     Corporate env.
>
>     I’ve searched for an official BestPractice on user  deletion
>     (leave company), but can’t find anything that is official-ish.
>
>     Two options:
>
>      1. Change user psswd to nonsense, then expire account.
>      2. DROP user.
>
>     There are +/- to both.
>
>     I prefer #1, as it gives the exact timestamp of expire (protects
>     company and ex-employee), but corporate auditors disagree.
>
>     What do you do?  Any official guidance on this?
>
>
> The five account systems I've had experience with (OpenVMS, Linux, 
> Active Directory, SQL Server, Postgresql) all have the ability to 
> expire users, and to unexpire them if the person ever returns.  (That 
> happened to me; my AD account was still there; they just reactivated 
> it...)
> In *every* audit that I've gone through (and I go through them *every 
> year* because of PCI) the auditors are perfectly happy to see that 
> accounts are disabled. Occasionally they ask to see the log entry 
> generated when one tries to log into Postgresql with an expired account.
>

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: Guidance on user deletion
  2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
  2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
  2024-05-12 10:56   ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
@ 2024-05-12 13:20     ` Ron Johnson <ronljohnsonjr@gmail.com>
  2024-05-12 13:41       ` Re: Guidance on user deletion David G. Johnston <david.g.johnston@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: Ron Johnson @ 2024-05-12 13:20 UTC (permalink / raw)
  To: vrms <vrms@netcologne.de>; +Cc: pgsql-admin@lists.postgresql.org

On Sun, May 12, 2024 at 6:56 AM vrms <vrms@netcologne.de> wrote:

>
> The five account systems I've had experience with (OpenVMS, Linux, Active
> Directory, SQL Server, Postgresql) all have the ability to expire users,
> and to unexpire them if the person ever returns.
>
> how do you practically expire an account in postgres?
>

ALTER ROLE ... VALID UNTIL 'timestamp';

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: Guidance on user deletion
  2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
  2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
  2024-05-12 10:56   ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
  2024-05-12 13:20     ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
@ 2024-05-12 13:41       ` David G. Johnston <david.g.johnston@gmail.com>
  0 siblings, 0 replies; 6+ messages in thread

From: David G. Johnston @ 2024-05-12 13:41 UTC (permalink / raw)
  To: Ron Johnson <ronljohnsonjr@gmail.com>; +Cc: vrms <vrms@netcologne.de>; pgsql-admin@lists.postgresql.org <pgsql-admin@lists.postgresql.org>

On Sunday, May 12, 2024, Ron Johnson <ronljohnsonjr@gmail.com> wrote:

> On Sun, May 12, 2024 at 6:56 AM vrms <vrms@netcologne.de> wrote:
>
>>
>> The five account systems I've had experience with (OpenVMS, Linux, Active
>> Directory, SQL Server, Postgresql) all have the ability to expire users,
>> and to unexpire them if the person ever returns.
>>
>> how do you practically expire an account in postgres?
>>
>
> ALTER ROLE ... VALID UNTIL 'timestamp';
>
>

I suppose, but that only expires the password, not invalidates the role.
There isn’t a concept of “invalid role”.  If you want to prevent a role
from being used to login remove the login attribute.

David J.

^ permalink  raw  reply  [nested|flat] 6+ messages in thread


end of thread, other threads:[~2024-05-12 13:41 UTC | newest]

Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew  (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-10 19:01 ` David G. Johnston <david.g.johnston@gmail.com>
2024-05-11 03:55 ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 10:56   ` vrms <vrms@netcologne.de>
2024-05-12 13:20     ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 13:41       ` David G. Johnston <david.g.johnston@gmail.com>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox