The EDB Postgres Advanced Server password file must not be used.
An XCCDF Rule
Description
The EDB Postgres password file can contain passwords to be used if the connection allows a password (and no password has been specified otherwise). This file contain lines of the following format: hostname:port:database:username:password It is critically important to system security that use of a password file be avoided as it stores passwords in plain text. Any user with access to these could potentially compromise the security of the database.
- ID
- SV-224173r879887_rule
- Version
- EP11-00-004850
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Remove any password files present on the server and implement a more secure form of authentication.
The DoD standard for authentication is DoD-approved PKI certificates.