{"Entry":{"collection":"guc","key":"md5_password_warnings","name":"md5_password_warnings","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"17","status":"added","to":"18"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"69acdc944aa8c08730cb97925669d9c4876f65e64640cb86640589c002e91f83","context":"","default_changed_in":[],"default_history":[{"from":"18","to":"19","value":"on"}],"editorial":{"advice":{"olap":"Use the same rule for analytical roles: a silent legacy driver may continue authenticating with an old MD5 verifier without generating this warning, so test and rotate those credentials explicitly.","oltp":"Keep md5_password_warnings on, but treat each warning only as evidence that a password-setting statement created or supplied an MD5 verifier. Separately inventory existing verifier types and test every authentication path before enforcing SCRAM-only access.","small":"Leave the warning enabled; its cost is negligible. Do not mistake an empty warning stream for proof that no MD5 verifiers or MD5-only clients remain."},"mechanism":["md5_password_warnings controls a PostgreSQL 18 deprecation WARNING emitted when CREATE ROLE or ALTER ROLE sets an MD5-encrypted password. It does not report authentication with an existing MD5 verifier and is therefore not an inventory of active MD5 clients or roles.","It is a USER-context setting, so an authorized role can change it for the current session and ALTER ROLE or ALTER DATABASE can establish future-session defaults. The warning can only arise in a session that both performs a password-setting statement and has the setting enabled.","password_encryption controls the format generated when plaintext passwords are set, while existing pg_authid verifiers remain unchanged until their passwords are reset. Migration therefore needs a protected verifier inventory, client compatibility testing, and credential rotation in addition to this warning."],"pitfalls":["Assuming the warning fires when an existing MD5 verifier is used for authentication; it fires only when CREATE ROLE or ALTER ROLE sets one.","Using the absence of warnings as proof that the cluster has no MD5 secrets or MD5-only clients.","Disabling the warning in deployment sessions that create or rotate roles and thereby hiding new MD5 verifier creation.","Changing password_encryption without rotating existing role passwords, which leaves their stored verifier format unchanged."],"references":[{"title":"PostgreSQL 19 Beta 4: md5_password_warnings","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-MD5-PASSWORD-WARNINGS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","scram_iterations","authentication_timeout","oauth_validator_libraries","krb_server_keyfile"],"summary":"md5_password_warnings is the PostgreSQL setting that controls whether PostgreSQL enables deprecation warnings for MD5 passwords."},"enumvals":[],"first_version":"18","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.76947+08:00","intro_commit":{"authored_at":"2024-12-02T13:30:07-06:00","discussion":["https://postgr.es/m/ZwbfpJJol7lDWajL%40nathan"],"hash":"db6a4a985bc09d260d5c29848e3c97f080646a53","subject":"Deprecate MD5 passwords.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=db6a4a985bc09d260d5c29848e3c97f080646a53"},"key":"md5_password_warnings","last_version":"20","max_val":"","min_val":"","name":"md5_password_warnings","position":291,"present_in":["18","19","20"],"short_desc":"Controls whether a WARNING about MD5 password deprecation is produced when a CREATE ROLE or ALTER ROLE statement sets an MD5-encrypted password.","short_desc_zh":"","source_rev":"english-manuals:29883d364e63f0a9b902cb950954179de09ad7cab268a60eca3da0457ac9b896","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"md5_password_warnings","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"md5_password_warnings","SourceRevision":"english-manuals:29883d364e63f0a9b902cb950954179de09ad7cab268a60eca3da0457ac9b896","Facts":{"boot_val":"on","category":"Connections and Authentication / Authentication","context":"user","description":"Controls whether a WARNING about MD5 password deprecation is produced when a CREATE ROLE or ALTER ROLE statement sets an MD5-encrypted password. The default value is on.","doc":{"anchor":"GUC-MD5-PASSWORD-WARNINGS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"md5_password_warnings","short_desc":"Enables deprecation warnings for MD5 passwords.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-MD5-PASSWORD-WARNINGS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"md5_password_warnings","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"md5_password_warnings","Summary":"","BodyHTML":"\u003cp\u003e控制在\u003ccode\u003eCREATE ROLE\u003c/code\u003e或\u003ccode\u003eALTER ROLE\u003c/code\u003e语句设置 MD5 加密密码时，是否生成有关 MD5 密码已弃用的\u003ccode\u003eWARNING\u003c/code\u003e。默认值为\u003ccode\u003eon\u003c/code\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"ee1c5bd11c2606c2bf1cd3b84ba0c9bcc71da2e70f65664ce2ba6d30c860b185","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e控制在\u003ccode class=\"command\"\u003eCREATE ROLE\u003c/code\u003e或\u003ccode class=\"command\"\u003eALTER ROLE\u003c/code\u003e语句设置 MD5 加密密码时，是否生成有关 MD5 密码已弃用的\u003ccode class=\"literal\"\u003eWARNING\u003c/code\u003e。默认值为\u003ccode class=\"literal\"\u003eon\u003c/code\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
