Defaulting password encryption for version above 14 #1406
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
See https://www.postgresql.org/docs/14/runtime-config-connection.html#GUC-PASSWORD-ENCRYPTION
Note: That this change is will upgrade the password hashes to use
scram-sha-256
if a postgres version 14 or higher is used,update_password
is set to true and cleartext passwords are used.It will not change pre-hashed passwords.
If you want to force a default password_encryption you can set
postgresql::server::password_encryption
to the wanted one.Note: The function
postgresql::postgresql_password
still has a hard default ofmd5
as hash type. Usepostgresql::server::password_encryption
as fourth parameter when using it on your own to ensure you use the version based default one.