pg.ddx.io pgsql-hackers@postgresql.org mailing list archive
help / color / mirror / Atom feedfix notes about password encryption in pg_authid docs
6+ messages / 2 participants
[nested] [flat]
* fix notes about password encryption in pg_authid docs
@ 2025-06-02 14:16 Nathan Bossart <nathandbossart@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: Nathan Bossart @ 2025-06-02 14:16 UTC (permalink / raw)
To: pgsql-hackers
I noticed that the docs for the pg_authid catalog still indicate that
passwords might be stored "unencrypted," which hasn't been possible since
commit eb61136. The attached patch attempts to fix that. If acceptable,
I'd back-patch it to all supported versions.
--
nathan
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-02 14:21 Nathan Bossart <nathandbossart@gmail.com>
parent: Nathan Bossart <nathandbossart@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: Nathan Bossart @ 2025-06-02 14:21 UTC (permalink / raw)
To: pgsql-hackers
On Mon, Jun 02, 2025 at 09:16:10AM -0500, Nathan Bossart wrote:
> I noticed that the docs for the pg_authid catalog still indicate that
> passwords might be stored "unencrypted," which hasn't been possible since
> commit eb61136. The attached patch attempts to fix that. If acceptable,
> I'd back-patch it to all supported versions.
And now with a patch actually attached...
--
nathan
From 268dc1afbcb1195de6b9aa735d9e27449c2e8fd2 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v1 1/1] doc: Fix notes about password encryption in pg_authid.
---
doc/src/sgml/catalogs.sgml | 7 +------
1 file changed, 1 insertion(+), 6 deletions(-)
diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
<structfield>rolpassword</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. The format depends
+ Encrypted password; null if none. The format depends
on the form of encryption used.
</para></entry>
</row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable><iteration count></replaceable>:<replaceable>&l
<replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
</para>
-
- <para>
- A password that does not follow either of those formats is assumed to be
- unencrypted.
- </para>
</sect1>
--
2.39.5 (Apple Git-154)
Attachments:
[text/plain] v1-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch (1.3K, ../../aD2zc-nj_UW5njzN@nathan/2-v1-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch)
download | inline diff:
From 268dc1afbcb1195de6b9aa735d9e27449c2e8fd2 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v1 1/1] doc: Fix notes about password encryption in pg_authid.
---
doc/src/sgml/catalogs.sgml | 7 +------
1 file changed, 1 insertion(+), 6 deletions(-)
diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
<structfield>rolpassword</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. The format depends
+ Encrypted password; null if none. The format depends
on the form of encryption used.
</para></entry>
</row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable><iteration count></replaceable>:<replaceable>&l
<replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
</para>
-
- <para>
- A password that does not follow either of those formats is assumed to be
- unencrypted.
- </para>
</sect1>
--
2.39.5 (Apple Git-154)
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-03 04:43 Michael Paquier <michael@paquier.xyz>
parent: Nathan Bossart <nathandbossart@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: Michael Paquier @ 2025-06-03 04:43 UTC (permalink / raw)
To: Nathan Bossart <nathandbossart@gmail.com>; +Cc: pgsql-hackers
On Mon, Jun 02, 2025 at 09:21:39AM -0500, Nathan Bossart wrote:
> On Mon, Jun 02, 2025 at 09:16:10AM -0500, Nathan Bossart wrote:
>> I noticed that the docs for the pg_authid catalog still indicate that
>> passwords might be stored "unencrypted," which hasn't been possible since
>> commit eb61136. The attached patch attempts to fix that. If acceptable,
>> I'd back-patch it to all supported versions.
Good point.
You are missing one reference in doc/src/sgml/system-views.sgml for
pg_shadow.passwd, no?
--
Michael
Attachments:
[application/pgp-signature] signature.asc (832B, ../../aD59Y1IXEDpq_j5C@paquier.xyz/2-signature.asc)
download
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-03 18:01 Nathan Bossart <nathandbossart@gmail.com>
parent: Michael Paquier <michael@paquier.xyz>
0 siblings, 1 reply; 6+ messages in thread
From: Nathan Bossart @ 2025-06-03 18:01 UTC (permalink / raw)
To: Michael Paquier <michael@paquier.xyz>; +Cc: pgsql-hackers
On Tue, Jun 03, 2025 at 01:43:15PM +0900, Michael Paquier wrote:
> You are missing one reference in doc/src/sgml/system-views.sgml for
> pg_shadow.passwd, no?
Yup. Here is an updated patch.
--
nathan
From 2d41fa2cff14b548905e2dfdd98b992976137e61 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v2 1/1] doc: Fix notes about password encryption in pg_authid.
---
doc/src/sgml/catalogs.sgml | 7 +------
doc/src/sgml/system-views.sgml | 2 +-
2 files changed, 2 insertions(+), 7 deletions(-)
diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
<structfield>rolpassword</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. The format depends
+ Encrypted password; null if none. The format depends
on the form of encryption used.
</para></entry>
</row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable><iteration count></replaceable>:<replaceable>&l
<replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
</para>
-
- <para>
- A password that does not follow either of those formats is assumed to be
- unencrypted.
- </para>
</sect1>
diff --git a/doc/src/sgml/system-views.sgml b/doc/src/sgml/system-views.sgml
index b58c52ea50f..986ae1f543d 100644
--- a/doc/src/sgml/system-views.sgml
+++ b/doc/src/sgml/system-views.sgml
@@ -3932,7 +3932,7 @@ SELECT * FROM pg_locks pl LEFT JOIN pg_prepared_xacts ppx
<structfield>passwd</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. See
+ Encrypted password; null if none. See
<link linkend="catalog-pg-authid"><structname>pg_authid</structname></link>
for details of how encrypted passwords are stored.
</para></entry>
--
2.39.5 (Apple Git-154)
Attachments:
[text/plain] v2-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch (1.9K, ../../aD84lmS0uLheXrk7@nathan/2-v2-0001-doc-Fix-notes-about-password-encryption-in-pg_aut.patch)
download | inline diff:
From 2d41fa2cff14b548905e2dfdd98b992976137e61 Mon Sep 17 00:00:00 2001
From: Nathan Bossart <nathan@postgresql.org>
Date: Mon, 2 Jun 2025 09:08:24 -0500
Subject: [PATCH v2 1/1] doc: Fix notes about password encryption in pg_authid.
---
doc/src/sgml/catalogs.sgml | 7 +------
doc/src/sgml/system-views.sgml | 2 +-
2 files changed, 2 insertions(+), 7 deletions(-)
diff --git a/doc/src/sgml/catalogs.sgml b/doc/src/sgml/catalogs.sgml
index cbd4e40a320..d53e7e39b59 100644
--- a/doc/src/sgml/catalogs.sgml
+++ b/doc/src/sgml/catalogs.sgml
@@ -1582,7 +1582,7 @@
<structfield>rolpassword</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. The format depends
+ Encrypted password; null if none. The format depends
on the form of encryption used.
</para></entry>
</row>
@@ -1627,11 +1627,6 @@ SCRAM-SHA-256$<replaceable><iteration count></replaceable>:<replaceable>&l
<replaceable>ServerKey</replaceable> are in Base64 encoded format. This format is
the same as that specified by <ulink url="https://datatracker.ietf.org/doc/html/rfc5803">RFC 5803</ulink>.
</para>
-
- <para>
- A password that does not follow either of those formats is assumed to be
- unencrypted.
- </para>
</sect1>
diff --git a/doc/src/sgml/system-views.sgml b/doc/src/sgml/system-views.sgml
index b58c52ea50f..986ae1f543d 100644
--- a/doc/src/sgml/system-views.sgml
+++ b/doc/src/sgml/system-views.sgml
@@ -3932,7 +3932,7 @@ SELECT * FROM pg_locks pl LEFT JOIN pg_prepared_xacts ppx
<structfield>passwd</structfield> <type>text</type>
</para>
<para>
- Password (possibly encrypted); null if none. See
+ Encrypted password; null if none. See
<link linkend="catalog-pg-authid"><structname>pg_authid</structname></link>
for details of how encrypted passwords are stored.
</para></entry>
--
2.39.5 (Apple Git-154)
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-04 05:11 Michael Paquier <michael@paquier.xyz>
parent: Nathan Bossart <nathandbossart@gmail.com>
0 siblings, 1 reply; 6+ messages in thread
From: Michael Paquier @ 2025-06-04 05:11 UTC (permalink / raw)
To: Nathan Bossart <nathandbossart@gmail.com>; +Cc: pgsql-hackers
On Tue, Jun 03, 2025 at 01:01:58PM -0500, Nathan Bossart wrote:
> Yup. Here is an updated patch.
Looks fine to me.
--
Michael
Attachments:
[application/pgp-signature] signature.asc (832B, ../../aD_Vm8q_BwvoCt9I@paquier.xyz/2-signature.asc)
download
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: fix notes about password encryption in pg_authid docs
@ 2025-06-04 14:52 Nathan Bossart <nathandbossart@gmail.com>
parent: Michael Paquier <michael@paquier.xyz>
0 siblings, 0 replies; 6+ messages in thread
From: Nathan Bossart @ 2025-06-04 14:52 UTC (permalink / raw)
To: Michael Paquier <michael@paquier.xyz>; +Cc: pgsql-hackers
On Wed, Jun 04, 2025 at 02:11:55PM +0900, Michael Paquier wrote:
> Looks fine to me.
Committed, thanks.
--
nathan
^ permalink raw reply [nested|flat] 6+ messages in thread
end of thread, other threads:[~2025-06-04 14:52 UTC | newest]
Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2025-06-02 14:16 fix notes about password encryption in pg_authid docs Nathan Bossart <nathandbossart@gmail.com>
2025-06-02 14:21 ` Nathan Bossart <nathandbossart@gmail.com>
2025-06-03 04:43 ` Michael Paquier <michael@paquier.xyz>
2025-06-03 18:01 ` Nathan Bossart <nathandbossart@gmail.com>
2025-06-04 05:11 ` Michael Paquier <michael@paquier.xyz>
2025-06-04 14:52 ` Nathan Bossart <nathandbossart@gmail.com>
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox