Re: [HACKERS] trust authentication behavior

2015-05-18 Thread Kohei KaiGai
2015-05-18 15:15 GMT+09:00 Denis Kirjanov : > > > - Ursprüngliche Mail - > Von: "Kohei KaiGai" > An: "Robert Haas" > CC: "David G. Johnston" , "Denis Kirjanov" > , pgsql-hackers@postgresql.org, "Kohei KaiGai" >

Re: [HACKERS] trust authentication behavior

2015-05-17 Thread Denis Kirjanov
- Ursprüngliche Mail - Von: "Kohei KaiGai" An: "Robert Haas" CC: "David G. Johnston" , "Denis Kirjanov" , pgsql-hackers@postgresql.org, "Kohei KaiGai" Gesendet: Samstag, 16. Mai 2015 03:32:55 Betreff: Re: [HACKERS] trust authenticati

Re: [HACKERS] trust authentication behavior

2015-05-15 Thread Kohei KaiGai
2015-05-16 5:13 GMT+09:00 Robert Haas : > On Thu, May 14, 2015 at 3:52 PM, David G. Johnston > wrote: >> On Thu, May 14, 2015 at 12:22 PM, Denis Kirjanov wrote: >>> >>> Yeah, but the idea is to do that without the pg_hba.conf >> >> You may want to try describing the problem and not just ask if th

Re: [HACKERS] trust authentication behavior

2015-05-15 Thread Robert Haas
On Thu, May 14, 2015 at 3:52 PM, David G. Johnston wrote: > On Thu, May 14, 2015 at 12:22 PM, Denis Kirjanov wrote: >> >> Yeah, but the idea is to do that without the pg_hba.conf > > You may want to try describing the problem and not just ask if the chosen > solution is possible - of which I am d

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread David G. Johnston
On Thu, May 14, 2015 at 12:22 PM, Denis Kirjanov wrote: > Yeah, but the idea is to do that without the pg_hba.conf > You may want to try describing the problem and not just ask if the chosen solution is possible - of which I am doubtful but I have never used selinux or studied it in any depth.

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread Denis Kirjanov
Yeah, but the idea is to do that without the pg_hba.conf - Ursprüngliche Mail - Von: "David G. Johnston" An: "Denis Kirjanov" CC: pgsql-hackers@postgresql.org Gesendet: Donnerstag, 14. Mai 2015 18:22:45 Betreff: Re: [HACKERS] trust authentication behavior On Thu,

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread Tom Lane
Andrew Dunstan writes: > On 05/14/2015 11:59 AM, Robert Haas wrote: >> On Thu, May 14, 2015 at 5:16 AM, Denis Kirjanov wrote: >>> Is it possible to restrict the trust auth method to accept local >>> connections only using the selinux policy? >> I would guess that it probably is, but I can't tel

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread Andrew Dunstan
On 05/14/2015 11:59 AM, Robert Haas wrote: On Thu, May 14, 2015 at 5:16 AM, Denis Kirjanov wrote: Is it possible to restrict the trust auth method to accept local connections only using the selinux policy? I would guess that it probably is, but I can't tell you how. I would have guessed n

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread Robert Haas
On Thu, May 14, 2015 at 5:16 AM, Denis Kirjanov wrote: > Is it possible to restrict the trust auth method to accept local connections > only using the selinux policy? I would guess that it probably is, but I can't tell you how. -- Robert Haas EnterpriseDB: http://www.enterprisedb.com The Enter

Re: [HACKERS] trust authentication behavior

2015-05-14 Thread David G. Johnston
On Thu, May 14, 2015 at 2:16 AM, Denis Kirjanov wrote: > Hello guys, > > Is it possible to restrict the trust auth method to accept local > connections only using the selinux policy? > You want selinux to prevent trust connections from non-local clients even if pg_hba.conf explicitly allows them

[HACKERS] trust authentication behavior

2015-05-14 Thread Denis Kirjanov
Hello guys, Is it possible to restrict the trust auth method to accept local connections only using the selinux policy? Thank you! -- Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-hackers