Re: Proposal: Support custom authentication methods using hooks

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: Proposal: Support custom authentication methods using hooks
Дата
Msg-id 9f017d59-c3f8-5d7a-beba-ef7304bd8cf9@enterprisedb.com
обсуждение исходный текст
Ответ на Proposal: Support custom authentication methods using hooks  (samay sharma <smilingsamay@gmail.com>)
Ответы Re: Proposal: Support custom authentication methods using hooks  ("Jonathan S. Katz" <jkatz@postgresql.org>)
Re: Proposal: Support custom authentication methods using hooks  (Andres Freund <andres@anarazel.de>)
Список pgsql-hackers
On 17.02.22 20:25, samay sharma wrote:
> A use case where this is useful are environments where you want 
> authentication to be centrally managed across different services. This 
> is a common deployment model for cloud providers where customers like to 
> use single sign on and authenticate across different services including 
> Postgres. Implementing this now is tricky as it requires syncing that 
> authentication method's credentials with Postgres (and that gets 
> trickier with TTL/expiry etc.). With these hooks, you can implement an 
> extension to check credentials directly using the 
> authentication provider's APIs.

We already have a variety of authentication mechanisms that support 
central management: LDAP, PAM, Kerberos, Radius.  What other mechanisms 
are people thinking about implementing using these hooks?  Maybe there 
are a bunch of them, in which case a hook system might be sensible, but 
if there are only one or two plausible ones, we could also just make 
them built in.




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Proposal: Support custom authentication methods using hooks
Следующее
От: Dagfinn Ilmari Mannsåker
Дата:
Сообщение: Re: psql: Make SSL info display more compact