Re: pgaudit - an auditing extension for PostgreSQL

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: pgaudit - an auditing extension for PostgreSQL
Дата
Msg-id 24636.1399216377@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: pgaudit - an auditing extension for PostgreSQL  (Stephen Frost <sfrost@snowman.net>)
Ответы Re: pgaudit - an auditing extension for PostgreSQL
Re: pgaudit - an auditing extension for PostgreSQL
Список pgsql-hackers
Stephen Frost <sfrost@snowman.net> writes:
> * Abhijit Menon-Sen (ams@2ndquadrant.com) wrote:
>> 1. I wish it were possible to prevent even the superuser from disabling
>> audit logging once it's enabled, so that if someone gained superuser
>> access without authorisation, their actions would still be logged.
>> But I don't think there's any way to do this.

> Their actions should be logged up until they disable auditing and
> hopefully those logs would be sent somewhere that they're unable to
> destroy (eg: syslog).  Of course, we make that difficult by not
> supporting log targets based on criteria (logging EVERYTHING to syslog
> would suck).

> I don't see a way to fix this, except to minimize the amount of things
> requiring superuser to reduce the chances of it being compromised, which
> is something I've been hoping to see happen for a long time.

Prohibiting actions to the superuser is a fundamentally flawed concept.
If you do that, you just end up having to invent a new "more super"
kind of superuser who *can* do whatever it is that needs to be done.
        regards, tom lane



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Amit Kapila
Дата:
Сообщение: Re: Per table autovacuum vacuum cost limit behaviour strange
Следующее
От: Euler Taveira
Дата:
Сообщение: Re: pg_shmem_allocations view