Re: initdb recommendations

"Jonathan S. Katz" <[email protected]>
Newsgroups gmane.comp.db.postgresql.devel.documentation
Message-ID <[email protected]>
On 4/8/19 8:44 AM, Magnus Hagander wrote:
> On Mon, Apr 8, 2019 at 2:41 PM Jonathan S. Katz <[email protected]
> <mailto:[email protected]>> wrote:
> 
>     On 4/8/19 8:25 AM, Peter Eisentraut wrote:
>     > On 2019-04-05 18:11, Jonathan S. Katz wrote:
>     >> +    <para>
>     >> +      We recommend using the <option>-W</option>,
>     <option>--pwprompt</option>,
>     >> +      or <option>--pwfile</option> flags to assign a password to
>     the database
>     >> +      superuser, and to override the
>     <filename>pg_hba.conf</filename> default
>     >> +      generation using <option>-auth-local peer</option> for
>     local connections,
>     >> +      and <option>-auth-host scram-sha-256</option> for remote
>     connections. See
>     >> +      <xref linkend="client-authentication"/> for more
>     information on client
>     >> +      authentication methods.
>     >> +    </para>
>     >
>     > As discussed on hackers, we are not ready to support scram-sha-256 out
>     > of the box.  So this advice, or any similar advice elsewhere,
>     would need
>     > to recommend "md5" as the setting --- which would probably be
>     embarrassing.
> 
>     Well, it's less embarrassing than trust, and we currently state:
> 
> 
> Yes. Much less.
> 
> 
>     "Also, specify -A md5 or -A password so that the default trust
>     authentication mode is not used"[1]
> 
>     We could also modify it to say :
> 
>     "and <option>-auth-host scram-sha-256</option> for remote connections if
>      your client supports it, otherwise <option>-auth-host md5</option>"
> 
> 
> That would be the best from a correctness, but if of course also makes
> things sound more complicated. I'm not sure where the right balance is
> there.

We could link here[1] from the docs on the line for "client supports it"

Jonathan

[1] https://wiki.postgresql.org/wiki/List_of_drivers
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE+oS2la8r95ogZD/x8QSccp8cZScFAlyrQogACgkQ8QSccp8c
ZSfeEw/8Cco3Lzgoei1n6lt5rbv7UdVzLLKm543x9renFSHVeiFeaCA7D4htJuy0
iZkOJk4C58ju73XEzIKcZAIImF+r9B+ziQWwRGe7UivWvLA82yg89iTyVYxfzw/z
U4LFdbkPbECehepJiWcF5uEM/wGRcufk0V7xNc842Rl0cjCPh2MopTQ3ewDiN2bh
XEScfDg0T5/GcFQyFc190xISklEb+3avLffh6WfrlccRSyqO85asHazgKLE6HZAQ
1PreaB0Mq4gQhzHX8Fn2P6dDs2PVFHAmlft4R1gJhfL4lHJn/6DCf/rXPbbpzaEy
AdkE65/ND1tIbBNEV484uEtMlynUi+vyBJ67gE/k4ckt9XQBRSop2xpblw7MsIZz
o/FMA4Gl4cIsP1ArU8TSXb9+3mSVKhnHwVjvFdgmbfNmezV3LboXz6shbptP5db2
U5KUAkDflrp/11l7shuj1yY4dVmDoTXRleToDMoHlcapfAWFMWexAqU89D6jsbFH
YCKiqQUImY3+asEdWeY8MZjhIltflDHq8Cf6GPQR9/GsTJUNs4dOJbFCGzg64lLg
2O8fzyw/Pn1f/gfcauAZO31tLCoYYTEMAH/GIz7SgqSaY1DznxXpUp40XKOunOty
vOrAgbQ3JwfUX2SCUIQzE4RryZmxM9ycdDQBm5vW+SHfBsJfxvs=
=MLnX
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.