Re: LDAP Authentication

Поиск
Список
Период
Сортировка
От Stephen Frost
Тема Re: LDAP Authentication
Дата
Msg-id ZOeqUuGbYOyA7KCy@tamriel.snowman.net
обсуждение исходный текст
Ответ на Re: LDAP Authentication  (Emile Amewoto <emileam@yahoo.com>)
Ответы Re: LDAP Authentication
Список pgsql-general
Greetings,

* Emile Amewoto (emileam@yahoo.com) wrote:
> Here is the high level  process:
> 1- Create the user x without password in Postgres.
> 2- Assign  role or roles to the user x
> 3- Update pg_hba.conf with the ldap connection link.
>
> You might need cert for the ldap to connect to AD, assuming you are using AD.

If you're using AD, you should *really* be using Kerberos/gssapi for
your authentication and *not* LDAP.  LDAP is insecure as it involves
passing around the user's credentials which is extremely bad practice
and is strongly discouraged.  LDAP auth also involves in-line round
trips to the LDAP server which can delay or even fail database
connections in the event that the LDAP server is even temporarily
unavailable.

Thanks,

Stephen

Вложения

В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Materialized view refreshing problem
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: Will PostgreSQL 16 supports native transparent data encryption ?