Re: postgres_fdw and Kerberos authentication

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: postgres_fdw and Kerberos authentication
Дата
Msg-id 17978.1464752802@sss.pgh.pa.us
обсуждение исходный текст
Ответ на postgres_fdw and Kerberos authentication  (Jean-Marc Lessard <Jean-Marc.Lessard@ultra-ft.com>)
Ответы Re: postgres_fdw and Kerberos authentication  (Stephen Frost <sfrost@snowman.net>)
Список pgsql-general
Jean-Marc Lessard <Jean-Marc.Lessard@ultra-ft.com> writes:
> A nice way to meet security requirements would be to provide single sign on support for the postgres_fdw.
> As long as you have defined a user in the source and destination databases, and configure the Kerberos authentication
youshould be able to use postgres_fdw. 

It's not really that easy, because postgres_fdw (like the server in
general) is running as the database-owner operating system user.
How will you associate a Postgres role that's responsible for a
particular connection request with some Kerberos credentials,
while keeping it away from credentials that belong to other roles?

This is certainly something that'd be useful to have, but it's not
clear how to do it in a secure fashion.

            regards, tom lane


В списке pgsql-general по дате отправления:

Предыдущее
От: Jim Longwill
Дата:
Сообщение: Re: Checkpoint Err on Startup of Rsynced System
Следующее
От: sri harsha
Дата:
Сообщение: Change in order of criteria - reg