2007-10-02 03:06:48 +08:00
|
|
|
$PostgreSQL: pgsql/contrib/chkpass/README.chkpass,v 1.5 2007/10/01 19:06:48 darcy Exp $
|
2001-05-03 20:32:13 +08:00
|
|
|
|
|
|
|
Chkpass is a password type that is automatically checked and converted upon
|
2007-10-01 14:52:42 +08:00
|
|
|
entry. It is stored encrypted. To compare, simply compare against a clear
|
2001-05-03 20:32:13 +08:00
|
|
|
text password and the comparison function will encrypt it before comparing.
|
|
|
|
It also returns an error if the code determines that the password is easily
|
|
|
|
crackable. This is currently a stub that does nothing.
|
|
|
|
|
|
|
|
I haven't worried about making this type indexable. I doubt that anyone
|
|
|
|
would ever need to sort a file in order of encrypted password.
|
|
|
|
|
|
|
|
If you precede the string with a colon, the encryption and checking are
|
|
|
|
skipped so that you can enter existing passwords into the field.
|
|
|
|
|
|
|
|
On output, a colon is prepended. This makes it possible to dump and reload
|
|
|
|
passwords without re-encrypting them. If you want the password (encrypted)
|
|
|
|
without the colon then use the raw() function. This allows you to use the
|
|
|
|
type with things like Apache's Auth_PostgreSQL module.
|
|
|
|
|
2005-09-23 23:05:04 +08:00
|
|
|
The encryption uses the standard Unix function crypt(), and so it suffers
|
|
|
|
from all the usual limitations of that function; notably that only the
|
|
|
|
first eight characters of a password are considered.
|
|
|
|
|
2007-10-02 03:06:48 +08:00
|
|
|
Here is some sample usage:
|
|
|
|
|
|
|
|
test=# create table test (p chkpass);
|
|
|
|
CREATE TABLE
|
|
|
|
test=# insert into test values ('hello');
|
|
|
|
INSERT 0 1
|
|
|
|
test=# select * from test;
|
|
|
|
p
|
|
|
|
----------------
|
|
|
|
:dVGkpXdOrE3ko
|
|
|
|
(1 row)
|
|
|
|
|
|
|
|
test=# select raw(p) from test;
|
|
|
|
raw
|
|
|
|
---------------
|
|
|
|
dVGkpXdOrE3ko
|
|
|
|
(1 row)
|
|
|
|
|
|
|
|
test=# select p = 'hello' from test;
|
|
|
|
?column?
|
|
|
|
----------
|
|
|
|
t
|
|
|
|
(1 row)
|
|
|
|
|
|
|
|
test=# select p = 'goodbye' from test;
|
|
|
|
?column?
|
|
|
|
----------
|
|
|
|
f
|
|
|
|
(1 row)
|
|
|
|
|
2001-05-03 20:32:13 +08:00
|
|
|
D'Arcy J.M. Cain
|
|
|
|
darcy@druid.net
|
|
|
|
|