Re: Patch to include PAM support... - Mailing list pgsql-patches

From Bruce Momjian
Subject Re: Patch to include PAM support...
Date
Msg-id 200106121655.f5CGt4320744@candle.pha.pa.us
Whole thread Raw
In response to Re: Patch to include PAM support...  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-patches
> Bruce Momjian <pgman@candle.pha.pa.us> writes:
> > I know there was concerns about blocking but is that problem any more so
> > than other interfaces we already support?
>
> We don't need to make it worse.  We've already had trouble reports about
> postmaster hangups with broken IDENT servers; PAM will hugely expand the
> scope of potential troubles.  Can you say "denial of service"?

Does it really?  You are saying PAM can make "denial of service" attacks
even easier than ident?

If it is the same risk, I think it is OK, but if it is worse, I see your
point.  (I don't know much about PAM except it allows authentication.)

--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026

pgsql-patches by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: Australian timezone configure option
Next
From: Chris Dunlop
Date:
Subject: Re: Australian timezone configure option