PostgreSQL码农集散地

PostgreSQL 18 preview - pgcrypto 新增2个更安全的密码哈希算法

PostgreSQL 18 preview - pgcrypto 新增2个更安全的密码哈希算法

pgcrypto 是 PostgreSQL 的一个官方扩展,提供了一系列加密函数,包括密码哈希、数据加密/解密等功能。

pgcrypto 的一些应用如下:

  • 《使用 PostgreSQL 大对象和pgcrypto加解密文件》
  • 《PostgreSQL pgcrypto 对称加密、非对称加密用法介绍》
  • 《Greenplum , PostgreSQL pgcrypto 加密算法、mode、PAD的选择 - 与Oracle, MySQL的差异(安全性差异)》
  • 《PostgreSQL 和 Greenplum pgcrypto 加解密bytea处理差异(convert, convert_from)》
  • 《固若金汤 - PostgreSQL pgcrypto加密插件》

PostgreSQL 18 pgcrypto 插件添加2个更安全的密码哈希算法:sha256crypt 和 sha512crypt。

https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=749a9e20c9790006f3af47f7a8faf4ad8dc358d9

Add modern SHA-2 based password hashes to pgcrypto.  
author Álvaro Herrera <[email protected]>   
Sat, 5 Apr 2025 17:16:58 +0000 (19:16 +0200)  
committer Álvaro Herrera <[email protected]>   
Sat, 5 Apr 2025 17:17:13 +0000 (19:17 +0200)  
commit 749a9e20c9790006f3af47f7a8faf4ad8dc358d9  
tree f06c2be00fe91ac6edead896d7981b8b4c76b11e tree  
parent e33f2335a9d9754ccf3bf7181085cfa581ee03c3 commit | diff  
Add modern SHA-2 based password hashes to pgcrypto.  

This adapts the publicly available reference implementation on  
https://www.akkadia.org/drepper/SHA-crypt.txt and adds the new hash
algorithms sha256crypt and sha512crypt to crypt() and gen_salt()  
respectively.  

Author: Bernd Helmle <[email protected]>  
Reviewed-by: Japin Li <[email protected]>  
Discussion: https://postgr.es/m/[email protected]  

AI 解读

补丁名称:Add modern SHA-2 based password hashes to pgcrypto. (向 pgcrypto 添加基于 SHA-2 的现代密码哈希)

核心内容:

这个补丁为 PostgreSQL 的 pgcrypto 扩展添加了两种新的密码哈希算法:sha256crypt 和 sha512crypt。

  • pgcrypto 是什么?

    • 它是 PostgreSQL 的一个官方扩展,提供了一系列加密函数,包括密码哈希、数据加密/解密等功能。
  • 添加了什么?

    • 新增了两种基于 SHA-2 哈希家族(具体是 SHA-256 和 SHA-512)的密码哈希算法。这些算法通常用于现代 Linux 和 Unix 系统中存储用户密码。
    • 它们的实现是基于一个公开的、广泛使用的参考实现(来自 https://www.akkadia.org/drepper/SHA-crypt.txt),确保了兼容性和标准化。
  • 如何使用?

    • 用户现在可以在 pgcrypto 的 crypt() 函数中使用这两个新算法来对密码进行哈希处理。
    • 同时,gen_salt() 函数也得到了更新,可以生成适用于 sha256crypt 和 sha512crypt 算法的盐值(salt)。生成正确的盐值对于这些哈希算法的安全性至关重要。
  • 为什么重要?

    • 安全性: SHA-2 (SHA-256, SHA-512) 相对于一些旧的哈希算法(如 MD5 或传统的 DES crypt)提供了显著更高的安全性,更能抵抗现代的密码破解技术(如彩虹表、暴力破解)。
    • 现代化:pgcrypto 加入对这些现代标准哈希算法的支持,使其功能与当前业界推荐的安全实践保持一致。
    • 兼容性: 允许 PostgreSQL 应用程序更容易地处理或验证那些遵循 SHA-crypt 标准存储的密码(例如,与系统用户账户集成时)。

总结:

这个补丁通过引入 sha256crypt 和 sha512crypt 这两种基于 SHA-2 的现代密码哈希算法,增强了 pgcrypto 扩展的功能和安全性。用户现在可以使用 crypt() 和 gen_salt() 函数来利用这些更强大的哈希方法来保护密码。