pg.ddx.io pgsql-admin@postgresql.org mailing list archive
help / color / mirror / Atom feedGuidance on user deletion
6+ messages / 4 participants
[nested] [flat]
* Guidance on user deletion
@ 2024-05-10 15:13 Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-10 19:01 ` Re: Guidance on user deletion David G. Johnston <david.g.johnston@gmail.com>
2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
0 siblings, 2 replies; 6+ messages in thread
From: Wetmore, Matthew (CTR) @ 2024-05-10 15:13 UTC (permalink / raw)
To: pgsql-admin@lists.postgresql.org <pgsql-admin@lists.postgresql.org>
Corporate env.
I've searched for an official BestPractice on user deletion (leave company), but can't find anything that is official-ish.
Two options:
1. Change user psswd to nonsense, then expire account.
2. DROP user.
There are +/- to both.
I prefer #1, as it gives the exact timestamp of expire (protects company and ex-employee), but corporate auditors disagree.
What do you do? Any official guidance on this?
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: Guidance on user deletion
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
@ 2024-05-10 19:01 ` David G. Johnston <david.g.johnston@gmail.com>
1 sibling, 0 replies; 6+ messages in thread
From: David G. Johnston @ 2024-05-10 19:01 UTC (permalink / raw)
To: Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>; +Cc: pgsql-admin@lists.postgresql.org
On Fri, May 10, 2024, 11:37 Wetmore, Matthew (CTR) <
Matthew.Wetmore@evernorth.com> wrote:
> Corporate env.
>
>
>
> I’ve searched for an official BestPractice on user deletion (leave
> company), but can’t find anything that is official-ish.
>
>
>
> Two options:
>
>
>
> 1. Change user psswd to nonsense, then expire account.
> 2. DROP user.
>
>
>
> There are +/- to both.
>
>
>
> I prefer #1, as it gives the exact timestamp of expire (protects company
> and ex-employee), but corporate auditors disagree.
>
>
>
> What do you do? Any official guidance on this?
>
>
>
Use proper off-machine audit logs to make the auditors happy then drop
stuff no longer has relevance.
David J.
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: Guidance on user deletion
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
@ 2024-05-11 03:55 ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 10:56 ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
1 sibling, 1 reply; 6+ messages in thread
From: Ron Johnson @ 2024-05-11 03:55 UTC (permalink / raw)
To: Pgsql-admin <pgsql-admin@lists.postgresql.org>
On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR) <
Matthew.Wetmore@evernorth.com> wrote:
> Corporate env.
>
>
>
> I’ve searched for an official BestPractice on user deletion (leave
> company), but can’t find anything that is official-ish.
>
>
>
> Two options:
>
>
>
> 1. Change user psswd to nonsense, then expire account.
> 2. DROP user.
>
>
>
> There are +/- to both.
>
>
>
> I prefer #1, as it gives the exact timestamp of expire (protects company
> and ex-employee), but corporate auditors disagree.
>
>
>
> What do you do? Any official guidance on this?
>
The five account systems I've had experience with (OpenVMS, Linux, Active
Directory, SQL Server, Postgresql) all have the ability to expire users,
and to unexpire them if the person ever returns. (That happened to me; my
AD account was still there; they just reactivated it...)
In *every* audit that I've gone through (and I go through them *every
year* because
of PCI) the auditors are perfectly happy to see that accounts are
disabled. Occasionally they ask to see the log entry generated when one
tries to log into Postgresql with an expired account.
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: Guidance on user deletion
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
@ 2024-05-12 10:56 ` vrms <vrms@netcologne.de>
2024-05-12 13:20 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: vrms @ 2024-05-12 10:56 UTC (permalink / raw)
To: pgsql-admin@lists.postgresql.org
> The five account systems I've had experience with (OpenVMS, Linux,
> Active Directory, SQL Server, Postgresql) all have the ability to
> expire users, and to unexpire them if the person ever returns.
how do you practically expire an account in postgres?
On 5/11/24 5:55 AM, Ron Johnson wrote:
> On Fri, May 10, 2024 at 2:37 PM Wetmore, Matthew (CTR)
> <Matthew.Wetmore@evernorth.com> wrote:
>
> Corporate env.
>
> I’ve searched for an official BestPractice on user deletion
> (leave company), but can’t find anything that is official-ish.
>
> Two options:
>
> 1. Change user psswd to nonsense, then expire account.
> 2. DROP user.
>
> There are +/- to both.
>
> I prefer #1, as it gives the exact timestamp of expire (protects
> company and ex-employee), but corporate auditors disagree.
>
> What do you do? Any official guidance on this?
>
>
> The five account systems I've had experience with (OpenVMS, Linux,
> Active Directory, SQL Server, Postgresql) all have the ability to
> expire users, and to unexpire them if the person ever returns. (That
> happened to me; my AD account was still there; they just reactivated
> it...)
> In *every* audit that I've gone through (and I go through them *every
> year* because of PCI) the auditors are perfectly happy to see that
> accounts are disabled. Occasionally they ask to see the log entry
> generated when one tries to log into Postgresql with an expired account.
>
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: Guidance on user deletion
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 10:56 ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
@ 2024-05-12 13:20 ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 13:41 ` Re: Guidance on user deletion David G. Johnston <david.g.johnston@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: Ron Johnson @ 2024-05-12 13:20 UTC (permalink / raw)
To: vrms <vrms@netcologne.de>; +Cc: pgsql-admin@lists.postgresql.org
On Sun, May 12, 2024 at 6:56 AM vrms <vrms@netcologne.de> wrote:
>
> The five account systems I've had experience with (OpenVMS, Linux, Active
> Directory, SQL Server, Postgresql) all have the ability to expire users,
> and to unexpire them if the person ever returns.
>
> how do you practically expire an account in postgres?
>
ALTER ROLE ... VALID UNTIL 'timestamp';
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: Guidance on user deletion
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-11 03:55 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 10:56 ` Re: Guidance on user deletion vrms <vrms@netcologne.de>
2024-05-12 13:20 ` Re: Guidance on user deletion Ron Johnson <ronljohnsonjr@gmail.com>
@ 2024-05-12 13:41 ` David G. Johnston <david.g.johnston@gmail.com>
0 siblings, 0 replies; 6+ messages in thread
From: David G. Johnston @ 2024-05-12 13:41 UTC (permalink / raw)
To: Ron Johnson <ronljohnsonjr@gmail.com>; +Cc: vrms <vrms@netcologne.de>; pgsql-admin@lists.postgresql.org <pgsql-admin@lists.postgresql.org>
On Sunday, May 12, 2024, Ron Johnson <ronljohnsonjr@gmail.com> wrote:
> On Sun, May 12, 2024 at 6:56 AM vrms <vrms@netcologne.de> wrote:
>
>>
>> The five account systems I've had experience with (OpenVMS, Linux, Active
>> Directory, SQL Server, Postgresql) all have the ability to expire users,
>> and to unexpire them if the person ever returns.
>>
>> how do you practically expire an account in postgres?
>>
>
> ALTER ROLE ... VALID UNTIL 'timestamp';
>
>
I suppose, but that only expires the password, not invalidates the role.
There isn’t a concept of “invalid role”. If you want to prevent a role
from being used to login remove the login attribute.
David J.
^ permalink raw reply [nested|flat] 6+ messages in thread
end of thread, other threads:[~2024-05-12 13:41 UTC | newest]
Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-05-10 15:13 Guidance on user deletion Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
2024-05-10 19:01 ` David G. Johnston <david.g.johnston@gmail.com>
2024-05-11 03:55 ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 10:56 ` vrms <vrms@netcologne.de>
2024-05-12 13:20 ` Ron Johnson <ronljohnsonjr@gmail.com>
2024-05-12 13:41 ` David G. Johnston <david.g.johnston@gmail.com>
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox