| From: | Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> | 
|---|---|
| To: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> | 
| Cc: | Peter Eisentraut <peter_e(at)gmx(dot)net>, PostgreSQL-patches <pgsql-patches(at)postgresql(dot)org> | 
| Subject: | Re: Re: Proposal for encrypting pg_shadow passwords | 
| Date: | 2001-08-16 14:33:42 | 
| Message-ID: | 200108161433.f7GEXgn19165@candle.pha.pa.us | 
| Views: | Whole Thread | Raw Message | Download mbox | Resend email | 
| Thread: | |
| Lists: | pgsql-patches | 
> Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> writes:
> > We aren't.  I can do that, but have not discussed it yet.  If we do it
> > is clearly a protocol change.  How will old clients handle longer salt,
> > and how do I know if they are older if I don't bump up the protocol
> > version number?
> 
> All of this is under the aegis of a new auth method code, so it doesn't
> matter.  Either clients handle the new auth method, or they don't.
OK, I see how I can do that. I thought the salt was part of the startup
packet but I see now that it is send during the authentication request. 
I can make it longer, probably 6 characters:
		
	> 62^6
	        56800235584
I can get that out of an int4.  I will take a single rand() and break it
into bsd62 pieces.
> The problem with bumping the protocol version number is that it breaks
> client-to-server compatibility *whether or not a particular connection
> needs the new auth method*.  Eg, a new client will be unable to talk to
> an old server.  This is not good.
Why is this the case?  There is nothing in the new client code that will
conflict with an old server, right?  Is it something hardwired in the
client code?
-- 
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman(at)candle(dot)pha(dot)pa(dot)us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Tom Lane | 2001-08-16 14:52:05 | Re: Re: Proposal for encrypting pg_shadow passwords | 
| Previous Message | Tom Lane | 2001-08-16 14:20:20 | Re: Re: Proposal for encrypting pg_shadow passwords |