Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.80) (envelope-from ) id 1ZCuw3-0003Du-C1 for pgsql-general@arkaria.postgresql.org; Wed, 08 Jul 2015 19:23:11 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.84) (envelope-from ) id 1ZCuw2-0003mV-RO for pgsql-general@arkaria.postgresql.org; Wed, 08 Jul 2015 19:23:10 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84) (envelope-from ) id 1ZCuts-0003RA-Lr for pgsql-general@postgresql.org; Wed, 08 Jul 2015 19:20:56 +0000 Received: from hogranch.com ([75.101.82.47]) by magus.postgresql.org with esmtp (Exim 4.84) (envelope-from ) id 1ZCutk-0003Rp-Tb for pgsql-general@postgresql.org; Wed, 08 Jul 2015 19:20:56 +0000 Received: from [192.168.0.2] (porker [192.168.0.2]) by hogranch.com (8.11.6/8.11.6) with ESMTP id t68JKgH25643 for ; Wed, 8 Jul 2015 12:20:42 -0700 Subject: Re: [SQL] encrypt psql password in unix script To: pgsql-general@postgresql.org References: From: John R Pierce Message-ID: <559D7805.3050909@hogranch.com> Date: Wed, 8 Jul 2015 12:20:37 -0700 User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.0.1 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-HawgScanner-Information: Please contact the ISP for more information X-HawgScanner: Found to be clean X-Pg-Spam-Score: -2.6 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-general Precedence: bulk Sender: pgsql-general-owner@postgresql.org On 7/8/2015 12:01 PM, Steve Midgley wrote: > My suggestion is to put it in an environment variable and set that > variable from a shell startup script that is secured with permissions. > (http://www.postgresql.org/docs/9.4/static/libpq-envars.html) > that just moves the problem, now the plaintext password is in a script file somewhere, AND many OS's let other users see your environment. > If you can't do that, the only other method I've used is to setup > Postgres with Ansible, and store the Pg passwords in an ansible vault, > which is encrypted. Ansible asks for the decrypt key when it runs. > how would that work for unattended scripts, such as cron jobs ? -- john r pierce, recycling bits in santa cruz -- Sent via pgsql-general mailing list (pgsql-general@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-general