Re: BUG #9337: SSPI/GSSAPI with mismatched user names
От | Brian Crowell |
---|---|
Тема | Re: BUG #9337: SSPI/GSSAPI with mismatched user names |
Дата | |
Msg-id | CAAQkdDqrz_O9EE7QL7vpyC4Ti3qcWGLPPD8Ox+Gevrke9+0zqg@mail.gmail.com обсуждение исходный текст |
Ответ на | Re: BUG #9337: SSPI/GSSAPI with mismatched user names (Tom Lane <tgl@sss.pgh.pa.us>) |
Ответы |
Re: BUG #9337: SSPI/GSSAPI with mismatched user names
|
Список | pgsql-bugs |
On Mon, Feb 24, 2014 at 1:58 PM, Tom Lane <tgl@sss.pgh.pa.us> wrote: > I wonder whether there would be any value in an option for SSPI (and > maybe other auth methods) to say "after authentication is complete, > substitute the authenticated principal name for the database user > name" (possibly after realm-stripping, case-folding, etc). I humbly resubmit my ticket-in-the-startup-packet suggestion, which I'd hope would be easier, especially since any program not supplying it would fall back to the standard challenge auth mechanism. Like: 1. client -> server startup packet + GSSAPI="here's my ticket" 2. server -> client AuthenticationGSSContinue 3. client -> server password packet 4. server -> client AuthenticationOK But then I don't know what I'm talking about really :P (goes to read the protocol specs) --Brian
В списке pgsql-bugs по дате отправления: