Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1jc3ZW-0004zm-Rg for pgsql-pkg-yum@arkaria.postgresql.org; Fri, 22 May 2020 09:02:30 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1jc3ZU-0002Mr-Cy for pgsql-pkg-yum@arkaria.postgresql.org; Fri, 22 May 2020 09:02:28 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1jc3ZU-0002Mk-7i for pgsql-pkg-yum@lists.postgresql.org; Fri, 22 May 2020 09:02:28 +0000 Received: from forward3-smtp.messagingengine.com ([66.111.4.237]) by magus.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1jc3ZQ-0003rS-I7 for pgsql-pkg-yum@postgresql.org; Fri, 22 May 2020 09:02:27 +0000 Received: from compute1.internal (compute1.nyi.internal [10.202.2.41]) by mailforward.nyi.internal (Postfix) with ESMTP id EC59A194246E; Fri, 22 May 2020 05:02:21 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute1.internal (MEProxy); Fri, 22 May 2020 05:02:21 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=BZA3KUbqWx4dcMez80SOr6UDn9oAhRnxWG8NtWFi2 OE=; b=So1co1AjvGbPGrjIjDJ3Br+HNPrzS8kT6/HGwaF8hi2avgJPnRh9HQ+Ea NfEFShwn7IKrT8J1O1LSO0jeodkwpYqPWO/y1x2roe/Ha7OKmjQ5h7O0keAOW5tw bq2luZYEEm4W9z5eJTgvAELezvgLDpneTU58MwLT0UwjEDrW6DDg5feEbNEkgOO7 yv/PsBmYISdeDsPSTMyTD9Uo6m78NtwGvyI+++eT6/uaqpwPb6r6hhRlV463aQpt ZDvkKU6iiGnr90g1NNQhU+DAtp/SLpyV+l0VUEa0JYuaskynOcAxRACso0+pPO2U 263Sn37WAS62Huwjy9Vf3TKXfb6eA== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduhedruddufedguddtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepuffvfhfhohfkffgfgggjtgfgsehtkeertddtfeejnecuhfhrohhmpefrvght vghrucfgihhsvghnthhrrghuthcuoehpvghtvghrrdgvihhsvghnthhrrghuthesvdhnug hquhgrughrrghnthdrtghomheqnecuggftrfgrthhtvghrnhepteeigfdtkeeffeekfeef hfehheekjeffuedvueetvedugfffheetteeiffelgffgnecuffhomhgrihhnpegtohhnfh drshhopddvnhguqhhurggurhgrnhhtrdgtohhmnecukfhppeelfedrvdegfedrkedvrddv geeinecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepph gvthgvrhdrvghishgvnhhtrhgruhhtsedvnhguqhhurggurhgrnhhtrdgtohhm X-ME-Proxy: Received: from april.pezone.net (p5df352f6.dip0.t-ipconnect.de [93.243.82.246]) by mail.messagingengine.com (Postfix) with ESMTPA id 251803065139; Fri, 22 May 2020 05:02:20 -0400 (EDT) Subject: Re: Can we stop defaulting to 'ident'? To: =?UTF-8?B?RGV2cmltIEfDvG5kw7x6?= , Stephen Frost References: <7761d006b5ace13a4d86ce489123e5004aaf8b6c.camel@gunduz.org> <20200519212710.GQ13712@tamriel.snowman.net> <6089d4c8e262dd6fe8a6510c283e674543a24b5c.camel@gunduz.org> <3869d8c9-c212-8d73-52f4-13b03abe4813@2ndquadrant.com> <20200520134035.GD296739@msg.df7cb.de> <3a7d55ed-6abb-2005-23d7-8411bb9f5651@2ndquadrant.com> <20200520145752.GD3418@tamriel.snowman.net> <32b7fe66-f0e6-42e5-3c95-7d123e7d7f6d@2ndquadrant.com> <0ef8211aac548796a5e66bf5d916966409e37457.camel@gunduz.org> Cc: Christoph Berg , Craig Ringer , pgsql-pkg-yum From: Peter Eisentraut Organization: 2ndQuadrant Message-ID: Date: Fri, 22 May 2020 11:02:19 +0200 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:52.0) Gecko/20100101 Thunderbird/52.9.1 MIME-Version: 1.0 In-Reply-To: <0ef8211aac548796a5e66bf5d916966409e37457.camel@gunduz.org> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 8bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Precedence: bulk On 2020-05-22 10:58, Devrim Gündüz wrote: > On Fri, 2020-05-22 at 10:52 +0200, Peter Eisentraut wrote: >> I found that if you use initdb's -A option to set the default >> authentication method, then the passsword_encryption setting is >> automatically adjusted in postgresql.conf. So this patch probably >> isn't even necessary. > > Right, but then it also sets scram auth for local connections as well > (which we don't want) > > That's why I am using --auth-local and --auth-host at the same time. It will also work if you set only one of --auth-local and --auth-host to scram-sha-256. -- Peter Eisentraut http://www.2ndQuadrant.com/ PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services