pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
fix notes about password encryption in pg_authid docs
6+ messages / 2 participants
[nested] [flat]

* fix notes about password encryption in pg_authid docs
@ 2025-06-02 14:16  Nathan Bossart <nathandbossart@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: Nathan Bossart @ 2025-06-02 14:16 UTC (permalink / raw)
  To: pgsql-hackers

I noticed that the docs for the pg_authid catalog still indicate that
passwords might be stored "unencrypted," which hasn't been possible since
commit eb61136.  The attached patch attempts to fix that.  If acceptable,
I'd back-patch it to all supported versions.

-- 
nathan





^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-02 14:21  Nathan Bossart <nathandbossart@gmail.com>
  parent: Nathan Bossart <nathandbossart@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: Nathan Bossart @ 2025-06-02 14:21 UTC (permalink / raw)
  To: pgsql-hackers

On Mon, Jun 02, 2025 at 09:16:10AM -0500, Nathan Bossart wrote:
> I noticed that the docs for the pg_authid catalog still indicate that
> passwords might be stored "unencrypted," which hasn't been possible since
> commit eb61136.  The attached patch attempts to fix that.  If acceptable,
> I'd back-patch it to all supported versions.

And now with a patch actually attached...

-- 
nathan
From 268dc1afbcb1195de6b9aa735d9e27449c2e8fd2 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v1 1/1] doc: Fix notes about password encryption in pg_authid.

---
 doc/src/sgml/catalogs.sgml | 7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
        <structfield>rolpassword</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none. The format depends
+       Encrypted password; null if none. The format depends
        on the form of encryption used.
       </para></entry>
      </row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable>&lt;iteration count&gt;</replaceable>:<replaceable>&l
    <replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
    the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
   </para>
-
-  <para>
-    A password that does not follow either of those formats is assumed to be
-    unencrypted.
-  </para>
  </sect1>
 
 
-- 
2.39.5 (Apple Git-154)

Attachments:

  [text/plain] v1-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch (1.3K, ../../aD2zc-nj_UW5njzN@nathan/2-v1-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch)
  download | inline diff:
From 268dc1afbcb1195de6b9aa735d9e27449c2e8fd2 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v1 1/1] doc: Fix notes about password encryption in pg_authid.

---
 doc/src/sgml/catalogs.sgml | 7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
        <structfield>rolpassword</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none. The format depends
+       Encrypted password; null if none. The format depends
        on the form of encryption used.
       </para></entry>
      </row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable>&lt;iteration count&gt;</replaceable>:<replaceable>&l
    <replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
    the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
   </para>
-
-  <para>
-    A password that does not follow either of those formats is assumed to be
-    unencrypted.
-  </para>
  </sect1>
 
 
-- 
2.39.5 (Apple Git-154)

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-03 04:43  Michael Paquier <michael@paquier.xyz>
  parent: Nathan Bossart <nathandbossart@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: Michael Paquier @ 2025-06-03 04:43 UTC (permalink / raw)
  To: Nathan Bossart <nathandbossart@gmail.com>; +Cc: pgsql-hackers

On Mon, Jun 02, 2025 at 09:21:39AM -0500, Nathan Bossart wrote:
> On Mon, Jun 02, 2025 at 09:16:10AM -0500, Nathan Bossart wrote:
>> I noticed that the docs for the pg_authid catalog still indicate that
>> passwords might be stored "unencrypted," which hasn't been possible since
>> commit eb61136.  The attached patch attempts to fix that.  If acceptable,
>> I'd back-patch it to all supported versions.

Good point.

You are missing one reference in doc/src/sgml/system-views.sgml for
pg_shadow.passwd, no?
--
Michael

Attachments:

  [application/pgp-signature] signature.asc (832B, ../../aD59Y1IXEDpq_j5C@paquier.xyz/2-signature.asc)
  download

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-03 18:01  Nathan Bossart <nathandbossart@gmail.com>
  parent: Michael Paquier <michael@paquier.xyz>
  0 siblings, 1 reply; 6+ messages in thread

From: Nathan Bossart @ 2025-06-03 18:01 UTC (permalink / raw)
  To: Michael Paquier <michael@paquier.xyz>; +Cc: pgsql-hackers

On Tue, Jun 03, 2025 at 01:43:15PM +0900, Michael Paquier wrote:
> You are missing one reference in doc/src/sgml/system-views.sgml for
> pg_shadow.passwd, no?

Yup.  Here is an updated patch.

-- 
nathan
From 2d41fa2cff14b548905e2dfdd98b992976137e61 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v2 1/1] doc: Fix notes about password encryption in pg_authid.

---
 doc/src/sgml/catalogs.sgml     | 7 +------
 doc/src/sgml/system-views.sgml | 2 +-
 2 files changed, 2 insertions(+), 7 deletions(-)

diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
        <structfield>rolpassword</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none. The format depends
+       Encrypted password; null if none. The format depends
        on the form of encryption used.
       </para></entry>
      </row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable>&lt;iteration count&gt;</replaceable>:<replaceable>&l
    <replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
    the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
   </para>
-
-  <para>
-    A password that does not follow either of those formats is assumed to be
-    unencrypted.
-  </para>
  </sect1>
 
 
diff --git a/doc/src/sgml/system-views.sgml b/doc/src/sgml/system-views.sgml
index b58c52ea50f..986ae1f543d 100644
--- a/doc/src/sgml/system-views.sgml
+++ b/doc/src/sgml/system-views.sgml
@@ -3932,7 +3932,7 @@ SELECT * FROM pg_locks pl LEFT JOIN pg_prepared_xacts ppx
        <structfield>passwd</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none.  See
+       Encrypted password; null if none.  See
        <link linkend="catalog-pg-authid"><structname>pg_authid</structname></link>
        for details of how encrypted passwords are stored.
       </para></entry>
-- 
2.39.5 (Apple Git-154)

Attachments:

  [text/plain] v2-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch (1.9K, ../../aD84lmS0uLheXrk7@nathan/2-v2-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch)
  download | inline diff:
From 2d41fa2cff14b548905e2dfdd98b992976137e61 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v2 1/1] doc: Fix notes about password encryption in pg_authid.

---
 doc/src/sgml/catalogs.sgml     | 7 +------
 doc/src/sgml/system-views.sgml | 2 +-
 2 files changed, 2 insertions(+), 7 deletions(-)

diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
        <structfield>rolpassword</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none. The format depends
+       Encrypted password; null if none. The format depends
        on the form of encryption used.
       </para></entry>
      </row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable>&lt;iteration count&gt;</replaceable>:<replaceable>&l
    <replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
    the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
   </para>
-
-  <para>
-    A password that does not follow either of those formats is assumed to be
-    unencrypted.
-  </para>
  </sect1>
 
 
diff --git a/doc/src/sgml/system-views.sgml b/doc/src/sgml/system-views.sgml
index b58c52ea50f..986ae1f543d 100644
--- a/doc/src/sgml/system-views.sgml
+++ b/doc/src/sgml/system-views.sgml
@@ -3932,7 +3932,7 @@ SELECT * FROM pg_locks pl LEFT JOIN pg_prepared_xacts ppx
        <structfield>passwd</structfield> <type>text</type>
       </para>
       <para>
-       Password (possibly encrypted); null if none.  See
+       Encrypted password; null if none.  See
        <link linkend="catalog-pg-authid"><structname>pg_authid</structname></link>
        for details of how encrypted passwords are stored.
       </para></entry>
-- 
2.39.5 (Apple Git-154)

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-04 05:11  Michael Paquier <michael@paquier.xyz>
  parent: Nathan Bossart <nathandbossart@gmail.com>
  0 siblings, 1 reply; 6+ messages in thread

From: Michael Paquier @ 2025-06-04 05:11 UTC (permalink / raw)
  To: Nathan Bossart <nathandbossart@gmail.com>; +Cc: pgsql-hackers

On Tue, Jun 03, 2025 at 01:01:58PM -0500, Nathan Bossart wrote:
> Yup.  Here is an updated patch.

Looks fine to me.
--
Michael

Attachments:

  [application/pgp-signature] signature.asc (832B, ../../aD_Vm8q_BwvoCt9I@paquier.xyz/2-signature.asc)
  download

^ permalink  raw  reply  [nested|flat] 6+ messages in thread

* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-04 14:52  Nathan Bossart <nathandbossart@gmail.com>
  parent: Michael Paquier <michael@paquier.xyz>
  0 siblings, 0 replies; 6+ messages in thread

From: Nathan Bossart @ 2025-06-04 14:52 UTC (permalink / raw)
  To: Michael Paquier <michael@paquier.xyz>; +Cc: pgsql-hackers

On Wed, Jun 04, 2025 at 02:11:55PM +0900, Michael Paquier wrote:
> Looks fine to me.

Committed, thanks.

-- 
nathan





^ permalink  raw  reply  [nested|flat] 6+ messages in thread


end of thread, other threads:[~2025-06-04 14:52 UTC | newest]

Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2025-06-02 14:16 fix notes about password encryption in pg_authid docs Nathan Bossart <nathandbossart@gmail.com>
2025-06-02 14:21 ` Nathan Bossart <nathandbossart@gmail.com>
2025-06-03 04:43   ` Michael Paquier <michael@paquier.xyz>
2025-06-03 18:01     ` Nathan Bossart <nathandbossart@gmail.com>
2025-06-04 05:11       ` Michael Paquier <michael@paquier.xyz>
2025-06-04 14:52         ` Nathan Bossart <nathandbossart@gmail.com>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox