1. Home
  2. Security Hardening
  3. EDB PostgreSQL Advanced Server V11 Windows OS V2R1
  4. EP11-00-004850 – The EDB Postgres Advanced Server password file must not be used.

EP11-00-004850 – The EDB Postgres Advanced Server password file must not be used.

Details

The EDB Postgres password file can contain passwords to be used if the connection allows a password (and no password has been specified otherwise).

This file contain lines of the following format:

hostname:port:database:username:password

It is critically important to system security that use of a password file be avoided as it stores passwords in plain text. Any user with access to these could potentially compromise the security of the database.

Solution

Remove any password files present on the server and implement a more secure form of authentication.

The DoD standard for authentication is DoD-approved PKI certificates.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles