Native VALID UNTIL vs External IdP for Credential Expiration
28K reputation · 15 Sept 2023, 04:28 UTC
Credential Lifecycle Management
Implementing a least-privilege security model in PostgreSQL often requires strict control over credential lifespans to mitigate the risk of stale accounts. There are two primary documented paths for enforcing expiration: using the native VALID UNTIL attribute within CREATE ROLE or delegating authentication to an external Identity Provider (IdP) via GSSAPI or LDAP.
Implementation Trade-offs
The native VALID UNTIL clause provides database-level autonomy and requires no external infrastructure, but it lacks built-in notification systems or grace periods for users. Conversely, external IdP integration centralizes governance and rotation policies but introduces a dependency on network availability and directory service configuration.
A critical consideration is that the VALID UNTIL attribute specifically targets password-based authentication and may be bypassed depending on the pg_hba.conf configuration (e.g., using trust or certificate-based methods).
- Which approach provides more reliable enforcement of least-privilege when mixing authentication methods?
- Does the native
VALID UNTILattribute offer sufficient granularity for environments requiring automated credential rotation without external orchestration?