Re: BUG #8375: pg_hba.conf: Include_dir like in postgresql.conf

Поиск
Список
Период
Сортировка
От Magnus Hagander
Тема Re: BUG #8375: pg_hba.conf: Include_dir like in postgresql.conf
Дата
Msg-id CABUevEx=hbO34g1GWf=vD8P2ipM_u3-uRYfo9RDDxJ=F=-HD0w@mail.gmail.com
обсуждение исходный текст
Ответ на Re: BUG #8375: pg_hba.conf: Include_dir like in postgresql.conf  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-bugs
On Thu, Aug 8, 2013 at 2:39 PM, Tom Lane <tgl@sss.pgh.pa.us> wrote:
> hv@tbz-pariv.de writes:
>> For easier deployment it would be nice to have an include_dir directive in
>> pg_hba.conf.
>
> This doesn't seem like a remarkably good idea from here, mainly because
> entries in pg_hba.conf are critically order-dependent.  Dropping random
> entries into a conf.d-like directory could produce unexpected results
> --- and in this case, "unexpected result" probably means "security
> failure".

If they are random, yes. You could easliy define them as ordered
though, by strict alphabetical ordering etc.

It's still a pretty decently sized footgun for people though, and I'm
not sure how useful it would actually be. And with the risk of
misconfiguration being a security hole rather than a badly configured
database (which would be the problem with a simliar thing for
postgresql.conf).

Perhaps the OP has a specific usecase to share where this would
actually be both safe and useful?

--
 Magnus Hagander
 Me: http://www.hagander.net/
 Work: http://www.redpill-linpro.com/

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Pavel Stehule
Дата:
Сообщение: Re: BUG #8329: UPDATE x SET x.y = x.y + z does not work in PL/pgSQL
Следующее
От: Michael Paquier
Дата:
Сообщение: Re: Recovery.conf PITR by recovery_target_time