Re: Adding line to pg_hba.conf for a specific group makes superuser authentication fail in 9.0? - Mailing list pgsql-admin

From Tom Lane
Subject Re: Adding line to pg_hba.conf for a specific group makes superuser authentication fail in 9.0?
Date
Msg-id 10638.1311784321@sss.pgh.pa.us
Whole thread Raw
In response to Adding line to pg_hba.conf for a specific group makes superuser authentication fail in 9.0?  (Glyn Astill <glynastill@yahoo.co.uk>)
Responses Re: Adding line to pg_hba.conf for a specific group makes superuser authentication fail in 9.0?  (Glyn Astill <glynastill@yahoo.co.uk>)
List pgsql-admin
Glyn Astill <glynastill@yahoo.co.uk> writes:
> I'm having what's hopefully a fairly trivial issue here with pg_hba.conf in 9.0.4; when I add in the following line

> ������� host    all         +ad_users   10.10.0.0/16          ldap <ldap details>

> If I try to log in with a superuser account from the 10.10.0.0/16 network it appears to try to authenticate it
againstthat entry via ldap. 

> This didn't happen in 8.4.8, what could I be missing?

Well, a superuser is automatically considered a member of any group,
so a match to that line would be expected IMO.  If you don't want that,
you need some more-specific line ahead of it to catch superusers.

            regards, tom lane

pgsql-admin by date:

Previous
From: Glyn Astill
Date:
Subject: Adding line to pg_hba.conf for a specific group makes superuser authentication fail in 9.0?
Next
From: A J
Date:
Subject: test commit_delay