Re: Security question : Database access control

Поиск
Список
Период
Сортировка
От Stephan Szabo
Тема Re: Security question : Database access control
Дата
Msg-id 20021022081942.K87361-100000@megazone23.bigpanda.com
обсуждение исходный текст
Ответ на Re: Security question : Database access control  ("Igor Georgiev" <gory@alphasoft-bg.com>)
Список pgsql-admin
On Tue, 22 Oct 2002, Igor Georgiev wrote:

> > >     edit *pg_hba.conf *
> > >         # Allow any user on the local system to connect to any
> > >         # database under any username, but only via an IP connection:
> > >         host         all         127.0.0.1     255.255.255.255    trust
> > >         # The same, over Unix-socket connections:
> > >         local        all                                          trust
> > what about reading pg_hba.conf comments?
> >            local    all                                              md5
> >
>
> Ok, but  my question actually isn't about pg_hba.conf comments, i read enough
> but what will stop root from adding this lines or doing su - postgres ??

Not much really.  But given that they have access to the raw data
files, preventing them access to the server doesn't gain you that
much if they really want to get the data.


В списке pgsql-admin по дате отправления:

Предыдущее
От: "Igor Georgiev"
Дата:
Сообщение: Re: Quickie about Database locations
Следующее
От: "Igor Georgiev"
Дата:
Сообщение: Re: Security question : Database access control