Re: Spoofing as the postmaster
От | Andrew Dunstan |
---|---|
Тема | Re: Spoofing as the postmaster |
Дата | |
Msg-id | 477669E5.9050505@dunslane.net обсуждение исходный текст |
Ответ на | Re: Spoofing as the postmaster ("D'Arcy J.M. Cain" <darcy@druid.net>) |
Ответы |
Re: Spoofing as the postmaster
Re: Spoofing as the postmaster |
Список | pgsql-hackers |
D'Arcy J.M. Cain wrote: > - 1: How does the client assure that the postmaster is legit > - 2: How does the postmaster assure that the client is legit > > > And neither answers the original problem: 3. How can the sysadmin prevent a malicious local user from hijacking the sockets if the postmaster isn't running? Prevention is much more valuable than ex post detection, IMNSHO. Probably the first answer is not to run postgres on a machine with untrusted users, but that's not always possible. Maybe we can't find a simple cross-platform answer, but that doesn't mean we should not look at platform-specific answers, at least for documentation. cheers andrew
В списке pgsql-hackers по дате отправления: