Re: Password policy

From: Andrew Dunstan <andrew(at)dunslane(dot)net>
To: "Roberts, Jon" <Jon(dot)Roberts(at)asurion(dot)com>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Password policy
Date: 2008-01-15 23:29:19
Message-ID: 478D41CF.3030801@dunslane.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Roberts, Jon wrote:
> I need to set a basic password policy for accounts but I don't see any
> documentation on how to do it. I'm assuming there is a way to do this,
> maybe even with a trigger.
>
> The policy would be something like this:
> 1. Must contain letters and numbers
> 2. Must be at least 8 characters long
> 3. Must contain one special character (#,@,$,%,!, etc)
> 4. Password (not the account) must expire after 90 days
> 5. Must warn users 10 days before the expire to change the password
>
>
>

This question really belongs on the -general list, not the -hackers list
(as do all questions about usage).

The short answer is "not really". You could use an external password
source like PAM or LDAP that enforced such restrictions.

cheers

andrew

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Sim Zacks 2008-01-15 23:54:39 Re: 8.2.4 serious slowdown
Previous Message Roberts, Jon 2008-01-15 22:11:16 Password policy