From 16ee9f455a4843b310bddfeda935b32c7b385e46 Mon Sep 17 00:00:00 2001 From: Ilia Ross Date: Mon, 24 Aug 2026 00:29:52 +0200 Subject: [PATCH] Fix PostgreSQL initialization to use SCRAM-SHA-256 auth by default https://forum.virtualmin.com/t/postgresql-defautl-install-issues/137798/3?u=ilia --- CHANGELOG.md | 1 + postgresql/postgresql-lib.pl | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index ce36adc2c..331f74258 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,7 @@ * Add options to send Webmin and Usermin errors to the systemd journal [forum.virtualmin.com/t/136562](https://forum.virtualmin.com/t/miniserv-webserver-log-growing-too-big-should-be-rotated/136562) * Add webserver logging controls to Usermin Configuration module * Add option to rotate Webmin and Usermin webserver logs using `logrotate` instead of periodically clearing them [#2821](https://github.com/webmin/webmin/pull/2821) +* Fix PostgreSQL initialization on EL systems to use SCRAM-SHA-256 authentication by default #### 2.660 (August 20, 2026) * Add support for creating `vfsv1` Linux quota files for limits above 4 TiB, while preserving existing quota file formats diff --git a/postgresql/postgresql-lib.pl b/postgresql/postgresql-lib.pl index 77c74b3c0..a54f64869 100755 --- a/postgresql/postgresql-lib.pl +++ b/postgresql/postgresql-lib.pl @@ -986,6 +986,11 @@ return undef; sub setup_postgresql { return undef if (!$config{'setup_cmd'}); +# Use SCRAM defaults for new clusters when supported by the EL setup wrapper +local $ENV{'PGSETUP_INITDB_OPTIONS'} = '--auth-host=scram-sha-256' + if ($config{'setup_cmd'} =~ /\bpostgresql-setup\b/ && + &get_postgresql_version(1) >= 10 && + !$ENV{'PGSETUP_INITDB_OPTIONS'}); local $temp = &transname(); local $rv = &system_logged("($config{'setup_cmd'}) >$temp 2>&1"); local $out = `cat $temp`;