Re: Password complexities in Postgres v14.6

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Password complexities in Postgres v14.6
Дата
Msg-id 3675887.1671203806@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Password complexities in Postgres v14.6  (Laurenz Albe <laurenz.albe@cybertec.at>)
Ответы Re: Password complexities in Postgres v14.6  (Magnus Hagander <magnus@hagander.net>)
Re: Password complexities in Postgres v14.6  (raf <raf@raf.org>)
Список pgsql-admin
Laurenz Albe <laurenz.albe@cybertec.at> writes:
> On Fri, 2022-12-16 at 17:57 +0530, Daulat wrote:
>> Any idea, how we can set some Password complexities in postgres for user password. Like, we can create profiles in
Oracle. 
>> I am looking to set the Password complexities  (one parameter from each line item has to be complied to):
>> Default password age for users: 90 days.
>> Password first letter will be alphabetic in uppercase.
>> English uppercase characters (A through Z)
>> English lowercase characters (a through z)
>> Base 10 digits (0 through 9)
>> Non-alphabetic characters ~" &_-+='! (){}[):;"'<>,.?/ !@#$%*
>> Password Minimum Length 8 character

> There is no reliable way to do this in PostgreSQL, since the server typically
> never sees the clear text password.
> You should consider using one of the other authentication methods like "ldap"
> and enforce the policy on the LDAP server.

Note that this approach typically leads to a net worsening of security.
Farming out the problem to LDAP means that the password has to be sent
in cleartext not only to the PG server, but then on to the LDAP server
(and in an awful lot of setups, that second hop isn't even done in an
encrypted connection).

You can fairly easily enforce password age limits in PG using the
ALTER USER ... VALID UNTIL option.  But for all this other stuff,
there is no way to enforce it at the server without sending passwords
in cleartext, which reduces security rather than increasing it.

In short: your security guidelines are obsolete and need an update.

            regards, tom lane



В списке pgsql-admin по дате отправления:

Предыдущее
От: Laurenz Albe
Дата:
Сообщение: Re: Password complexities in Postgres v14.6
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: Password complexities in Postgres v14.6