public inbox for [email protected]
help / color / mirror / Atom feedFrom: Stephen Frost <[email protected]>
To: Christoph Berg <[email protected]>
To: Peter Eisentraut <[email protected]>
To: Devrim Gündüz <[email protected]>
To: Craig Ringer <[email protected]>
To: pgsql-pkg-yum <[email protected]>
Subject: Re: Can we stop defaulting to 'ident'?
Date: Wed, 20 May 2020 10:45:04 -0400
Message-ID: <[email protected]> (raw)
In-Reply-To: <[email protected]>
References: <CAMsr+YFCuBGWh4=aM-K2LCsBEwcrqm=pphKKHEH09vHwXcspow@mail.gmail.com>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
Greetings,
* Christoph Berg ([email protected]) wrote:
> Re: Peter Eisentraut
> > The upstream default is still to use md5 passwords by default, and some
> > deliberation has gone into that to keep it that way. So it would make sense
> > to have the RPMs also do that. The Debian packages also still use md5.
> > Some consistency across the board would be good. Otherwise it will be very
> > confusing for users if everyone just goes into their own direction.
>
> The upstream initdb default is still 'trust', but everyone agrees that
> it's good that distributions are changing that so something more
> secure, so we are already disconnected from the "true" default here.
>
> We can move the Debian packages to scram as well, if that helps.
> I just haven't done that yet because I haven't read up on how a
> migration plan should look.
Yes, I think that would make a lot of sense. I'd be happy to chat about
what that would look like if it'd help.
I'd also vote for moving the upstream initdb default to scram too, of
course. It'd certainly be nice to get all of these things in line
together and there's really no good reason to be using md5 these days
for new installs (or, really, even for most old installs..).
Thanks,
Stephen
Attachments:
[application/pgp-signature] signature.asc (819B, 2-signature.asc)
download
view thread (54+ messages) latest in thread
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
Subject: Re: Can we stop defaulting to 'ident'?
In-Reply-To: <[email protected]>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox