Re: Use "samehost" by default in pg_hba.conf?

Поиск
Список
Период
Сортировка
От Stef Walter
Тема Re: Use "samehost" by default in pg_hba.conf?
Дата
Msg-id 4AC4B2F3.2010007@memberwebs.com
обсуждение исходный текст
Ответ на Use "samehost" by default in pg_hba.conf?  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Use "samehost" by default in pg_hba.conf?  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Tom Lane wrote:
> Now that the samehost/samenet patch is in, I wonder if it wouldn't be
> a good idea to replace this part of the default pg_hba.conf file:

You're probably not suggesting this, but I would be against a default
setting of 'samehost' used with 'trust'.

Essentially that would be the same as rlogin rsh, where if the user can
spoof a TCP connection, he can connect to postgresql. Depending on the
platform, an interface may have to be down for this to work.

Cheers,

Stef


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Boszormenyi Zoltan
Дата:
Сообщение: Re: CommitFest 2009-09, two weeks on
Следующее
От: Stef Walter
Дата:
Сообщение: Re: Use "samehost" by default in pg_hba.conf?