Re: Defaulting to password_encryption = scram-sha-256

2018-10-07 Thread Andres Freund
Hi, On 2018-10-07 11:37:20 -0400, Tom Lane wrote: > Michael Paquier writes: > > On Sat, Oct 06, 2018 at 11:43:06PM -0700, Andres Freund wrote: > >> Now that we probably have shaken the worst issues out of scram, > >> shouldn't we change the default password_encryption to something that > >> doesn

Re: Defaulting to password_encryption = scram-sha-256

2018-10-07 Thread Tom Lane
Michael Paquier writes: > On Sat, Oct 06, 2018 at 11:43:06PM -0700, Andres Freund wrote: >> Now that we probably have shaken the worst issues out of scram, >> shouldn't we change the default password_encryption to something that >> doesn't scare people? The only reason I could think of not wanti

Re: Defaulting to password_encryption = scram-sha-256

2018-10-07 Thread Michael Paquier
On Sat, Oct 06, 2018 at 11:43:06PM -0700, Andres Freund wrote: > Now that we probably have shaken the worst issues out of scram, > shouldn't we change the default password_encryption to something that > doesn't scare people? The only reason I could think of not wanting to > do that for is that we

Defaulting to password_encryption = scram-sha-256

2018-10-06 Thread Andres Freund
Hi, Now that we probably have shaken the worst issues out of scram, shouldn't we change the default password_encryption to something that doesn't scare people? The only reason I could think of not wanting to do that for is that we don't necessarily guarantee that we have a strong random generato