Re: Authentication in batch processing - Mailing list pgsql-admin

From Bruce Momjian
Subject Re: Authentication in batch processing
Date
Msg-id 200207100211.g6A2B8r13552@candle.pha.pa.us
Whole thread Raw
In response to Re: Authentication in batch processing  (Kevin Brannen <kevinb@nurseamerica.net>)
List pgsql-admin
Kevin Brannen wrote:
> Bruce Momjian wrote:
> ...
> >
> > 7.3 may remove PGPASSWORD, I think, and instead allow you to specify a
> > file that contains the password.
>
> But do you know how many hours it took me to find out about PGPASSWORD
> in the docs and now you want to change that? :-)
>
> How about all 4 approaches:  on the command-line, from an env-var, from
> a file, and finally prompting if there's a tty.  Pick any order you want
> on the first 3, but flexibility is important, and circumstances do
> change over time that may make 1 more desireable then the others.

PGPASSWORD is a security problem on platforms that can show environment
variables, mostly *BSD's, and most people don't know it is visible.

--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026

pgsql-admin by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: disk space
Next
From: "Nick Fankhauser"
Date:
Subject: Re: unsubscribe me for heavens sakes!!!!!!!!!