Re: [PoC/RFC] Multiple passwords, interval expirations - Mailing list pgsql-hackers

From Gurjeet Singh
Subject Re: [PoC/RFC] Multiple passwords, interval expirations
Date
Msg-id CABwTF4U-2YOuCnuud5sroAc2A8J4-4+9RsisJQ3zdTc8Ecz0hg@mail.gmail.com
Whole thread Raw
In response to Re: [PoC/RFC] Multiple passwords, interval expirations  (Bruce Momjian <bruce@momjian.us>)
Responses Re: [PoC/RFC] Multiple passwords, interval expirations
List pgsql-hackers
On Sun, Oct 8, 2023 at 10:29 AM Bruce Momjian <bruce@momjian.us> wrote:
>
> I was speaking of autoremoving in cases where we are creating a new one,
> and taking the previous new one and making it the old one, if that was
> not clear.

Yes, I think I understood it differently. I understood it to mean that
this behaviour would apply to all passwords, those created by existing
commands, as well as to those created by new commands for rollover use
case. Whereas you meant this autoremove behaviour to apply only to
those passwords created by/for rollover related commands. I hope I've
understood your proposal correctly this time around :-)

I believe the passwords created by rollover feature should
behave by the same rules as the rules for passwords created by
existing CREATE/ALTER ROLE commands. If we implement the behaviour to
delete expired passwords, then I believe that behaviour should apply
to all passwords, irrespective of which command/feature was used to
create a password.


Best regards,
Gurjeet
http://Gurje.et



pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: [PoC/RFC] Multiple passwords, interval expirations
Next
From: Noah Misch
Date:
Subject: Re: Trigger violates foreign key constraint