agora inbox for pgsql-sql@postgresql.org  
help / color / mirror / Atom feed
From: John R Pierce <pierce@hogranch.com>
To: pgsql-general@postgresql.org
Subject: Re: [SQL] encrypt psql password in unix script
Date: Wed, 8 Jul 2015 12:20:37 -0700
Message-ID: <559D7805.3050909@hogranch.com> (raw)
In-Reply-To: <CAJexoSKSz75caNVyYHdONYsjKYHCAN_ONknO6X7fOr8CVQfgNA@mail.gmail.com>
References: <CAJP7dtBTkFiF4h6E9jWKToBjRrRmVNWrEan5EmpGK+oBvt_4sQ@mail.gmail.com>
	<CAJexoSKSz75caNVyYHdONYsjKYHCAN_ONknO6X7fOr8CVQfgNA@mail.gmail.com>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-general>

On 7/8/2015 12:01 PM, Steve Midgley wrote:
> My suggestion is to put it in an environment variable and set that 
> variable from a shell startup script that is secured with permissions. 
> (http://www.postgresql.org/docs/9.4/static/libpq-envars.html)
>

that just moves the problem, now the plaintext password is in a script 
file somewhere, AND many OS's let other users see your environment.

> If you can't do that, the only other method I've used is to setup 
> Postgres with Ansible, and store the Pg passwords in an ansible vault, 
> which is encrypted. Ansible asks for the decrypt key when it runs.
>

how would that work for unattended scripts, such as cron jobs ?



-- 
john r pierce, recycling bits in santa cruz



-- 
Sent via pgsql-general mailing list (pgsql-general@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-general



view thread (6+ messages)

Message-ID: <559D7805.3050909@hogranch.com>
Permalink:  ../559D7805.3050909@hogranch.com/
Also on:    postgresql.org/message-id/559D7805.3050909@hogranch.com

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-sql@postgresql.org
  Cc: pierce@hogranch.com, pgsql-general@postgresql.org
  Subject: Re: [SQL] encrypt psql password in unix script
  In-Reply-To: <559D7805.3050909@hogranch.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox