Re: Why don't we allow DNS names in pg_hba.conf?
От | Tom Lane |
---|---|
Тема | Re: Why don't we allow DNS names in pg_hba.conf? |
Дата | |
Msg-id | 18463.1136312512@sss.pgh.pa.us обсуждение исходный текст |
Ответ на | Re: Why don't we allow DNS names in pg_hba.conf? (mark@mark.mielke.cc) |
Ответы |
Re: Why don't we allow DNS names in pg_hba.conf?
|
Список | pgsql-hackers |
mark@mark.mielke.cc writes: > On Tue, Jan 03, 2006 at 12:43:03PM -0500, Tom Lane wrote: >> I'm not sure about the relative usefulness of this compared to the >> forward-lookup case, nor whether it's riskier or less risky from a >> spoofing point of view. But something to consider. > I think it's riskier. I have my own PTR records, that I can make be > whatever I wish without any authority verifying that my actions are > proper. Yeah, that occurred to me after a few moments' thought. We could do one extra forward lookup to confirm that the reverse-lookup name maps back to the IP address. > It's not a big deal. Depends on how many names you want to put into pg_hba.conf. I don't offhand see a use-case for very many, but maybe there is one. Even if there are a lot, they'd not be expensive to look up if there is a local nameserver that is authoritative for those names ... which I'd think would be the normal case. The more "outside" names you've got in pg_hba.conf, the more open you are to spoofing. regards, tom lane
В списке pgsql-hackers по дате отправления: