Re: [GENERAL] SHA1 on postgres 8.3

From: Florian Weimer <fweimer(at)bfk(dot)de>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Marko Kreen <markokr(at)gmail(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, David Fetter <david(at)fetter(dot)org>, Greg Sabino Mullane <greg(at)turnstep(dot)com>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: [GENERAL] SHA1 on postgres 8.3
Date: 2008-01-29 08:10:13
Message-ID: 823ashvyqi.fsf@mid.bfk.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-hackers

* Bruce Momjian:

> I am not thrilled about moving _some_ of pgcrypto into the backend ---
> pgcrypto right now seems well designed and if we pull part of it out it
> seems it will be less clear than what we have now. Perhaps we just need
> to document that md5() isn't for general use and some function in
> pgcrypto should be used instead?

Yes, that would probably help those folks doing checklist-based
security audits.

--
Florian Weimer <fweimer(at)bfk(dot)de>
BFK edv-consulting GmbH http://www.bfk.de/
Kriegsstraße 100 tel: +49-721-96201-1
D-76133 Karlsruhe fax: +49-721-96201-99

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Håkan Jacobsson 2008-01-29 09:06:19 Re: Getting the count(*) from two tables and two date ranges in same query
Previous Message Marko Kreen 2008-01-29 08:06:45 Re: [GENERAL] SHA1 on postgres 8.3

Browse pgsql-hackers by date

  From Date Subject
Next Message Heikki Linnakangas 2008-01-29 08:20:41 Re: [PATCHES] Proposed patch: synchronized_scanningGUCvariable
Previous Message Marko Kreen 2008-01-29 08:06:45 Re: [GENERAL] SHA1 on postgres 8.3