Re: SCRAM auth and Pgpool-II

From: Chapman Flack <chap(at)anastigmatix(dot)net>
To: Tatsuo Ishii <ishii(at)sraoss(dot)co(dot)jp>
Cc: sfrost(at)snowman(dot)net, michael(dot)paquier(at)gmail(dot)com, robertmhaas(at)gmail(dot)com, pgsql-hackers(at)postgresql(dot)org
Subject: Re: SCRAM auth and Pgpool-II
Date: 2017-07-14 14:21:09
Message-ID: a8e4fbb6-35d6-42b7-e36e-a675e2b7b228@anastigmatix.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 07/13/2017 10:46 PM, Chapman Flack wrote:

> Neither is suitable on an unencrypted channel (as has been repeatedly

Please forgive my thinko about md5. I had overlooked the second
salted md5 used in the protocol, and that had to be some years ago
when I was sure I had looked for one in the code. But it's been there
since 2001, so I simply overlooked it somehow. Not sure how. I've had
an unnecessarily jaundiced view of "md5" auth for years as a result.

I feel much better now. Sorry for the noise.

-Chap

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Fabien COELHO 2017-07-14 14:37:13 Re: WIP Patch: Pgbench Serialization and deadlock errors
Previous Message Marina Polyakova 2017-07-14 13:48:29 Re: WIP Patch: Pgbench Serialization and deadlock errors