Re: initdb recommendations

From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>
Cc: PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>, Noah Misch <noah(at)leadboat(dot)com>, "Jonathan S(dot) Katz" <jkatz(at)postgresql(dot)org>
Subject: Re: initdb recommendations
Date: 2019-05-23 16:56:49
Message-ID: CABUevExdgYkaikDHFtkibqJ=pEamnqnTW_DDuBLoRmtsd9KR8w@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-docs pgsql-hackers

On Thu, May 23, 2019, 18:54 Peter Eisentraut <
peter(dot)eisentraut(at)2ndquadrant(dot)com> wrote:

> On 2019-04-06 20:08, Noah Misch wrote:
> >>> I think we should just change the defaults. There is a risk of warning
> >>> fatigue. initdb does warn about this, so anyone who cared could have
> >>> gotten the information.
> >>>
> >>
> >> I've been suggesting that for years, so definite strong +1 for doing
> that.
> >
> > +1
>
> To recap, the idea here was to change the default authentication methods
> that initdb sets up, in place of "trust".
>
> I think the ideal scenario would be to use "peer" for local and some
> appropriate password method (being discussed elsewhere) for host.
>
> Looking through the buildfarm, I gather that the only platforms that
> don't support peer are Windows, AIX, and HP-UX. I think we can probably
> figure out some fallback or alternative default for the latter two
> platforms without anyone noticing. But what should the defaults be on
> Windows? It doesn't have local sockets, so the lack of peer wouldn't
> matter. But is it OK to default to a password method, or would that
> upset people particularly?
>

I'm sure password would be fine there. It's what "everybody else" does
(well sqlserver also cord integrated security, but people are used to it).

/Magnus

In response to

Responses

Browse pgsql-docs by date

  From Date Subject
Next Message Tobias Bussmann 2019-05-23 21:50:12 Docs for Generated Columns
Previous Message Peter Eisentraut 2019-05-23 16:54:27 Re: initdb recommendations

Browse pgsql-hackers by date

  From Date Subject
Next Message Donald Dong 2019-05-23 17:05:29 Re: Why could GEQO produce plans with lower costs than the standard_join_search?
Previous Message Peter Eisentraut 2019-05-23 16:54:27 Re: initdb recommendations