Re: Why don't we allow DNS names in pg_hba.conf?

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Why don't we allow DNS names in pg_hba.conf?
Дата
Msg-id 18463.1136312512@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Why don't we allow DNS names in pg_hba.conf?  (mark@mark.mielke.cc)
Ответы Re: Why don't we allow DNS names in pg_hba.conf?  (Bruce Momjian <pgman@candle.pha.pa.us>)
Список pgsql-hackers
mark@mark.mielke.cc writes:
> On Tue, Jan 03, 2006 at 12:43:03PM -0500, Tom Lane wrote:
>> I'm not sure about the relative usefulness of this compared to the
>> forward-lookup case, nor whether it's riskier or less risky from a
>> spoofing point of view.  But something to consider.

> I think it's riskier. I have my own PTR records, that I can make be
> whatever I wish without any authority verifying that my actions are
> proper.

Yeah, that occurred to me after a few moments' thought.  We could do one
extra forward lookup to confirm that the reverse-lookup name maps back
to the IP address.

> It's not a big deal.

Depends on how many names you want to put into pg_hba.conf.  I don't
offhand see a use-case for very many, but maybe there is one.  Even
if there are a lot, they'd not be expensive to look up if there is
a local nameserver that is authoritative for those names ... which
I'd think would be the normal case.  The more "outside" names you've
got in pg_hba.conf, the more open you are to spoofing.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tino Wildenhain
Дата:
Сообщение: Re: Why don't we allow DNS names in pg_hba.conf?
Следующее
От: "Larry Rosenman"
Дата:
Сообщение: Re: Why don't we allow DNS names in pg_hba.conf?