Re: What are best practices wrt passwords? - Mailing list pgsql-general

From Alvaro Herrera
Subject Re: What are best practices wrt passwords?
Date
Msg-id 202410161437.sw2xkl37rcmz@alvherre.pgsql
Whole thread Raw
In response to What are best practices wrt passwords?  (mbork@mbork.pl)
List pgsql-general
On 2024-Oct-16, mbork@mbork.pl wrote:

> I understand why giving the password on the command line or in an
> environment variable is a security risk (because of `ps`), but I do not
> understand why `psql` doesn't have an option like `--password-command`
> accepting a command which then prints the password on stdout.  For
> example, I could then use `pass` (https://www.passwordstore.org/) with
> gpg-agent.

We had a patch to add PGPASSCOMMAND once:
https://www.postgresql.org/message-id/flat/CAE35ztOGZqgwae3mBA%3DL97pSg3kvin2xycQh%3Dir%3D5NiwCApiYQ%40mail.gmail.com

I don't remember the overall conclusions (other than the patch being
rejected), but maybe you can give that a read.

-- 
Álvaro Herrera         PostgreSQL Developer  —  https://www.EnterpriseDB.com/



pgsql-general by date:

Previous
From: felix.quintgz@yahoo.com
Date:
Subject: Re: What are best practices wrt passwords?
Next
From: mbork@mbork.pl
Date:
Subject: Re: What are best practices wrt passwords?