Re: Kerberos brokenness and oops question in 8.1beta2

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Kerberos brokenness and oops question in 8.1beta2
Дата
Msg-id 9827.1128722591@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Kerberos brokenness and oops question in 8.1beta2  ("Magnus Hagander" <mha@sollentuna.net>)
Список pgsql-hackers
"Magnus Hagander" <mha@sollentuna.net> writes:
> Anyway. This makes it impossible for a 8.1 client to connect to a 8.0
> server, or a 8.0 client to a 8.1 server, in any case where the service
> name has changed - such as a win32 active directory deployment, but I'm
> sure many others as well.

How important is that really?  How many win32 users are likely to be
using Kerberos auth with 8.0?

> The only real advantage to how it is now is that it's "cleaner". The
> argument that it protects against a security hole in MIT KRB5 doesn't
> hold any more because there is a patch out, and we can't take
> responsibility for people who haven't patched.

I don't really buy that argument.  ISTM we should fix the code to do the
right thing, especially if the right thing is more secure.  If I
understood what you said properly, hardwiring it as "postgres" is the
correct thing, and loss of compatibility in marginal cases is just the
price we pay for having done it wrong originally.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Magnus Hagander"
Дата:
Сообщение: Kerberos brokenness and oops question in 8.1beta2
Следующее
От: Neil Conway
Дата:
Сообщение: Re: Issue is changing _bt_compare function and