Re: Session Identifiers

Поиск
Список
Период
Сортировка
От oleg yusim
Тема Re: Session Identifiers
Дата
Msg-id CAKd4e_H58zuejWgONg1199TOO9yRZqUQ1Gp52aJVppb2jAs-wA@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Session Identifiers  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Session Identifiers  (Pavel Stehule <pavel.stehule@gmail.com>)
Список pgsql-general
Tom,

I understand the idea that for external communication you rely on SSL. However, how about me opening psql prompt into the database directly from my Linux box, my db is installed at? I thought, it would be considered local connection and would not go through the SSL channels. If that is the case, here we would be dealing with Session IDs belonging to DB itself, not OpenSSL. 

Please, correct me if I'm wrong.

Thanks,

Oleg

On Sun, Dec 20, 2015 at 11:28 AM, Tom Lane <tgl@sss.pgh.pa.us> wrote:
oleg yusim <olegyusim@gmail.com> writes:
> Got it, thanks... Now, is it any protection in place currently against
> replacing Session ID (my understanding, it is kept in memory, belonging to
> the session process) or against guessing Session ID (i.e. is Session ID
> generated using FIPS 140-2 compliant algorithms, or anything of that sort)?

I don't think Postgres even has any concept that matches what you seem
to think a Session ID is.

If you're looking for communication security/integrity checking, that's
something we leave to other software such as SSL.

                        regards, tom lane

В списке pgsql-general по дате отправления:

Предыдущее
От: Melvin Davidson
Дата:
Сообщение: Re: Session Identifiers
Следующее
От: oleg yusim
Дата:
Сообщение: Re: Session Identifiers