Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.80) (envelope-from ) id 1ZCuMl-0001Y5-Kv for pgsql-general@arkaria.postgresql.org; Wed, 08 Jul 2015 18:46:43 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.84) (envelope-from ) id 1ZCuMk-0003A6-Pa for pgsql-general@arkaria.postgresql.org; Wed, 08 Jul 2015 18:46:42 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84) (envelope-from ) id 1ZCuMj-00039f-4K for pgsql-general@postgresql.org; Wed, 08 Jul 2015 18:46:41 +0000 Received: from hogranch.com ([75.101.82.47]) by magus.postgresql.org with esmtp (Exim 4.84) (envelope-from ) id 1ZCuMf-0002lc-8i for pgsql-general@postgresql.org; Wed, 08 Jul 2015 18:46:40 +0000 Received: from [192.168.0.2] (porker [192.168.0.2]) by hogranch.com (8.11.6/8.11.6) with ESMTP id t68IkSH24991 for ; Wed, 8 Jul 2015 11:46:29 -0700 Subject: Re: encrypt psql password in unix script To: pgsql-general@postgresql.org References: From: John R Pierce Message-ID: <559D6FFF.5070903@hogranch.com> Date: Wed, 8 Jul 2015 11:46:23 -0700 User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.0.1 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-HawgScanner-Information: Please contact the ISP for more information X-HawgScanner: Found to be clean X-Pg-Spam-Score: -2.6 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-general Precedence: bulk Sender: pgsql-general-owner@postgresql.org On 7/8/2015 11:34 AM, Suresh Raja wrote: > I cannot use .pgpass as the password stored here is not encrypted. > > can i use a encrypted password from unix shell script. has anybody > ran into same situation. Wht options do i have. I believe anywhere you enter a password in postgres, it can be the hash instead. but what security does that gain you? if someone gets your encrypted/hashed password, he can still log on. the pgpass file has to be permissions 700, so only YOU (and root) can read it. if these are LOCAL connections to a pg server on the same machine, you can use 'ident' as your authentication, where your unix user is used as the postgres username. or, you can use ssl certificates for authentication, this is more complex to setup. -- john r pierce, recycling bits in santa cruz -- Sent via pgsql-general mailing list (pgsql-general@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-general