Re: Authenticating user `postgres'

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Authenticating user `postgres'
Дата
Msg-id 12232.1001683307@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Authenticating user `postgres'  (Arcady Genkin <a.genkin@utoronto.ca>)
Ответы Re: Authenticating user `postgres'
Список pgsql-general
Arcady Genkin <a.genkin@utoronto.ca> writes:
> Tom Lane <tgl@sss.pgh.pa.us> writes:
>> Offhand I'd think it foolish to make it easier to get into the
>> superuser account than regular accounts anyway.

> Not so much if the database only listens on unix domain socket, which
> has tight permissions, and a UNIX user has to identify himself with a
> valid password anyways.

So?  If you can trust local connections from the user who is superuser
to be correctly authenticated, then you can also trust local connections
from the users who are non-superusers.  I really completely fail to see
the point of requiring a password to connect to non-critical accounts
while having no password (*LESS* security) for the critical superuser
account.

            regards, tom lane

В списке pgsql-general по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: Re: postgresql.conf
Следующее
От: Mark kirkwood
Дата:
Сообщение: Re: Migrating to DB2 from Postgres