Re: security - user account setup on SUSE

Поиск
Список
Период
Сортировка
От Ivo Rossacher
Тема Re: security - user account setup on SUSE
Дата
Msg-id 200505121259.59927.rossacher@bluewin.ch
обсуждение исходный текст
Ответ на security - user account setup on SUSE  ("Brandon Fouts" <BFouts@psrc.org>)
Список pgsql-admin
Am Mittwoch, 11. Mai 2005 20:42 schrieb Brandon Fouts:
> I think for security reasons I should not run PostgreSQL from the root

yes.

> account. Also, as PostgreSQL will probably be only one of the applications
> running on this box. (would running in UML give me any extra security? - I
> suspect not the right tool??)

Don't think this helps by it self.

>
> IF I'm wrong to worry about root account, now is the time to inform me.
> Otherwise read on.
>
> (I have setup once and I think I had it running from the root account.)
>
> background SUSE 9 and YAST install of PostgreSQL creates the following
> directories:
>
> /usr/lib/postgresql/
> /usr/share/postgresql/
> /usr/share/pgsql/
> /var/lib/pgsql/backup
> /var/lib/pgsql/data
>
> and currently status shows unused
> # rcpostgresql status     unused        (rc - is this some kind of
> scripting??)
>
> Can anyone offer some guidance?

In the Yast tool you can start the servers you need in the Runlevel-Editor.
There you can select in which runnlevels you want it to run as well.
When you start it there, at startup a scritp will be executed with root
permission. This script will start then the Server with postgres as user. So
the database does not run under root permission (which would be definitly
bad).

Best regards
Ivo

>--------------------------(end of broadcast)---------------------------
> TIP 2: you can get off all lists at once with the unregister command
>     (send "unregister YourEmailAddressHere" to majordomo@postgresql.org)

В списке pgsql-admin по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: thats funny :)
Следующее
От: Bruno Wolff III
Дата:
Сообщение: Re: brute force attacking the password