Re: Authentication in batch processing

From: fuzzy(at)logon(dot)si (Alfred Anzlovar)
To: pgsql-admin(at)postgresql(dot)org
Subject: Re: Authentication in batch processing
Date: 2002-07-02 03:50:14
Message-ID: a09d3977.0207011950.4266647e@posting.google.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

pgman(at)candle(dot)pha(dot)pa(dot)us (Bruce Momjian) wrote in message news:<200206022022(dot)g52KM8m18308(at)candle(dot)pha(dot)pa(dot)us>...
> Password prompting was changed in 7.2.X. You can now pass a script into
> psql, and you will be prompted for the password on your terminal rather
> than having the password coming from the script.
>
> The best way send the password in 7.2.X is to use 'expect', or use the
> PGPASSWORD environment variable. (However, on some OS's, environment
> values like PGPASSWORD can be seen by 'ps'.) Another option is that if
> /dev/tty can't get opened, the password will be requested from stdin.
> Unfortunately, I can't think of an easy way to make /dev/tty fail.

I see it as a very radical change in password processing.

I know you must have your reasons to have it this way, but there are
people like Hal Lynch (or like me), to whom this change introduces
many new problems (and does not solve any of security ones).

It would be nice if there was an option (in psql) to use stdin instead of
/dev/tty to read password(s) (like before 7.2.X).

Is this too much to ask?

Thanks,
Alfred

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Werner Modenbach 2002-07-02 06:47:34 pg_dumpall in crontab doesn't work
Previous Message Robson 2002-07-01 18:39:10 Too many clients already.