Re: SSL over Unix-domain sockets

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: SSL over Unix-domain sockets
Дата
Msg-id 20080115122121.GC4473@alvh.no-ip.org
обсуждение исходный текст
Ответ на Re: SSL over Unix-domain sockets  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: SSL over Unix-domain sockets  (Aidan Van Dyk <aidan@highrise.ca>)
Список pgsql-hackers
Tom Lane wrote:

> It strikes me that given the postmaster's infrastructure for listening
> on multiple sockets, it would be a pretty small matter of programming
> to teach it to listen on socket files in multiple directories not only
> one.

The problem with this idea is that if the postmaster goes away, both
sockets go away, which means the attacker can place his socket in /tmp
as he sees fit.

-- 
Alvaro Herrera                                http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Alvaro Herrera
Дата:
Сообщение: Re: SSL over Unix-domain sockets
Следующее
От: Hannu Krosing
Дата:
Сообщение: Re: Declarative partitioning grammar