Hi,

While testing md5_password_warnings, I noticed that authentication
with an MD5-encrypted password emits the expected warning when the HBA
method is md5, but not when it is password.

Was this intentional, or just an oversight?

I couldn't find any discussion about this, so I put together the
attached patch. It updates the authentication code to emit the same
MD5 deprecation connection warning after successful password
authentication when the stored password is MD5-encrypted.

Thoughts?

Regards,

-- 
Fujii Masao

Attachment: v1-0001-Warn-on-password-auth-with-MD5-encrypted-password.patch
Description: Binary data

Reply via email to