Re: [HACKERS] Installation procedure wishes

Поиск
Список
Период
Сортировка
От wieck@debis.com (Jan Wieck)
Тема Re: [HACKERS] Installation procedure wishes
Дата
Msg-id m10utl0-0003kLC@orion.SAPserv.Hamburg.dsh.de
обсуждение исходный текст
Ответ на Re: [HACKERS] Installation procedure wishes  (Bruce Momjian <maillist@candle.pha.pa.us>)
Ответы Re: [HACKERS] Installation procedure wishest
Список pgsql-hackers
Bruce Momjian wrote:

>
> >     But if you have choosen the conservative way of beeing a site
> >     admin, noone will ever tell you if you forgot  to  DISABLE  a
> >     feature after a 50 hour restore marathon.
>
> Yes, the same reason postmaster -i flag is required to enable tcp/ip.

    That's  a detail I'm in doubt about. Our defaults for AF_UNIX
    sockets is trust (and AFAIK must  be  because  identd  cannot
    handle  them).  Thus  any  user who has a local shell account
    could easily become db user postgres.

    I think a default of host-localhost-ident-sameuser and giving
    superusers  the  builtin  right to become everyone would gain
    higher security.


Jan

--

#======================================================================#
# It's easier to get forgiveness for being wrong than for being right. #
# Let's break this rule - forgive me.                                  #
#========================================= wieck@debis.com (Jan Wieck) #

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Dmitry Samersoff
Дата:
Сообщение: Re: [HACKERS] Installation procedure wishes
Следующее
От: Zeugswetter Andreas IZ5
Дата:
Сообщение: Re: [HACKERS] New TODO item