agora inbox for pgsql-sql@postgresql.org
help / color / mirror / Atom feedencrypt psql password in unix script
6+ messages / 5 participants
[nested] [flat]
* encrypt psql password in unix script
@ 2015-07-08 18:34 Suresh Raja <suresh.rajaabc@gmail.com>
0 siblings, 2 replies; 6+ messages in thread
From: Suresh Raja @ 2015-07-08 18:34 UTC (permalink / raw)
To: pgsql-general@postgresql.org; pgsql-sql
Hi:
I cannot use .pgpass as the password stored here is not encrypted.
can i use a encrypted password from unix shell script. has anybody ran
into same situation. Wht options do i have.
Thanks,
-SR
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: encrypt psql password in unix script
@ 2015-07-08 18:46 John R Pierce <pierce@hogranch.com>
parent: Suresh Raja <suresh.rajaabc@gmail.com>
1 sibling, 1 reply; 6+ messages in thread
From: John R Pierce @ 2015-07-08 18:46 UTC (permalink / raw)
To: pgsql-general@postgresql.org
On 7/8/2015 11:34 AM, Suresh Raja wrote:
> I cannot use .pgpass as the password stored here is not encrypted.
>
> can i use a encrypted password from unix shell script. has anybody
> ran into same situation. Wht options do i have.
I believe anywhere you enter a password in postgres, it can be the hash
instead.
but what security does that gain you? if someone gets your
encrypted/hashed password, he can still log on. the pgpass file has to
be permissions 700, so only YOU (and root) can read it.
if these are LOCAL connections to a pg server on the same machine, you
can use 'ident' as your authentication, where your unix user is used as
the postgres username. or, you can use ssl certificates for
authentication, this is more complex to setup.
--
john r pierce, recycling bits in santa cruz
--
Sent via pgsql-general mailing list (pgsql-general@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-general
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: encrypt psql password in unix script
@ 2015-07-08 19:01 Steve Midgley <science@misuse.org>
parent: Suresh Raja <suresh.rajaabc@gmail.com>
1 sibling, 2 replies; 6+ messages in thread
From: Steve Midgley @ 2015-07-08 19:01 UTC (permalink / raw)
To: Suresh Raja <suresh.rajaabc@gmail.com>; +Cc: pgsql-general@postgresql.org; pgsql-sql
My suggestion is to put it in an environment variable and set that variable
from a shell startup script that is secured with permissions. (
http://www.postgresql.org/docs/9.4/static/libpq-envars.html)
If you can't do that, the only other method I've used is to setup Postgres
with Ansible, and store the Pg passwords in an ansible vault, which is
encrypted. Ansible asks for the decrypt key when it runs.
Steve
On Wed, Jul 8, 2015 at 11:34 AM, Suresh Raja <suresh.rajaabc@gmail.com>
wrote:
> Hi:
>
> I cannot use .pgpass as the password stored here is not encrypted.
>
> can i use a encrypted password from unix shell script. has anybody ran
> into same situation. Wht options do i have.
>
> Thanks,
> -SR
>
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: encrypt psql password in unix script
@ 2015-07-08 19:06 Vick Khera <vivek@khera.org>
parent: John R Pierce <pierce@hogranch.com>
0 siblings, 0 replies; 6+ messages in thread
From: Vick Khera @ 2015-07-08 19:06 UTC (permalink / raw)
To: John R Pierce <pierce@hogranch.com>; +Cc: pgsql-general <pgsql-general@postgresql.org>
On Wed, Jul 8, 2015 at 2:46 PM, John R Pierce <pierce@hogranch.com> wrote:
> but what security does that gain you? if someone gets your
> encrypted/hashed password, he can still log on. the pgpass file has to be
> permissions 700, so only YOU (and root) can read it.
>
Exactly this. If you want a script to authenticate to postgres (or anything
else) then somewhere you need something to be in the clear, whether it be
the key to decrypt the password or a private key. If you can't trust the
local file system and users, then you can't do what you want.
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: [SQL] encrypt psql password in unix script
@ 2015-07-08 19:08 Xavier Stevens <xavier@simple.com>
parent: Steve Midgley <science@misuse.org>
1 sibling, 0 replies; 6+ messages in thread
From: Xavier Stevens @ 2015-07-08 19:08 UTC (permalink / raw)
To: Steve Midgley <science@misuse.org>; +Cc: Suresh Raja <suresh.rajaabc@gmail.com>; PostgreSQL mailing lists <pgsql-general@postgresql.org>; pgsql-sql
I use envcrypt for things like this locally. Just encrypt the file with
your own PGP key.
https://github.com/whilp/envcrypt
On Wed, Jul 8, 2015 at 12:01 PM, Steve Midgley <science@misuse.org> wrote:
> My suggestion is to put it in an environment variable and set that
> variable from a shell startup script that is secured with permissions. (
> http://www.postgresql.org/docs/9.4/static/libpq-envars.html)
>
> If you can't do that, the only other method I've used is to setup Postgres
> with Ansible, and store the Pg passwords in an ansible vault, which is
> encrypted. Ansible asks for the decrypt key when it runs.
>
> Steve
>
>
> On Wed, Jul 8, 2015 at 11:34 AM, Suresh Raja <suresh.rajaabc@gmail.com>
> wrote:
>
>> Hi:
>>
>> I cannot use .pgpass as the password stored here is not encrypted.
>>
>> can i use a encrypted password from unix shell script. has anybody ran
>> into same situation. Wht options do i have.
>>
>> Thanks,
>> -SR
>>
>
>
^ permalink raw reply [nested|flat] 6+ messages in thread
* Re: [SQL] encrypt psql password in unix script
@ 2015-07-08 19:20 John R Pierce <pierce@hogranch.com>
parent: Steve Midgley <science@misuse.org>
1 sibling, 0 replies; 6+ messages in thread
From: John R Pierce @ 2015-07-08 19:20 UTC (permalink / raw)
To: pgsql-general@postgresql.org
On 7/8/2015 12:01 PM, Steve Midgley wrote:
> My suggestion is to put it in an environment variable and set that
> variable from a shell startup script that is secured with permissions.
> (http://www.postgresql.org/docs/9.4/static/libpq-envars.html)
>
that just moves the problem, now the plaintext password is in a script
file somewhere, AND many OS's let other users see your environment.
> If you can't do that, the only other method I've used is to setup
> Postgres with Ansible, and store the Pg passwords in an ansible vault,
> which is encrypted. Ansible asks for the decrypt key when it runs.
>
how would that work for unattended scripts, such as cron jobs ?
--
john r pierce, recycling bits in santa cruz
--
Sent via pgsql-general mailing list (pgsql-general@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-general
^ permalink raw reply [nested|flat] 6+ messages in thread
end of thread, other threads:[~2015-07-08 19:20 UTC | newest]
Thread overview: 6+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2015-07-08 18:34 encrypt psql password in unix script Suresh Raja <suresh.rajaabc@gmail.com>
2015-07-08 18:46 ` John R Pierce <pierce@hogranch.com>
2015-07-08 19:06 ` Vick Khera <vivek@khera.org>
2015-07-08 19:01 ` Steve Midgley <science@misuse.org>
2015-07-08 19:08 ` Xavier Stevens <xavier@simple.com>
2015-07-08 19:20 ` John R Pierce <pierce@hogranch.com>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox