Re: LDAP authentication fails with concurrent create extensions - Mailing list pgsql-bugs

From Stephen Frost
Subject Re: LDAP authentication fails with concurrent create extensions
Date
Msg-id 20180410113157.GL27724@tamriel.snowman.net
Whole thread Raw
In response to LDAP authentication fails with concurrent create extensions  (Greg k <gregg.kay@gmail.com>)
Responses Re: LDAP authentication fails with concurrent create extensions  (Greg k <gregg.kay@gmail.com>)
List pgsql-bugs
Greetings,

* Greg k (gregg.kay@gmail.com) wrote:
> We are using postgresql 10.3 on Centos 7.2 with LDAP authentication (samba4
> with AD domain controller). We've recently moved to LDAP authentication and
> are now encountering a problem where some concurrent connections that
> create extensions in different databases at the same time are failing with
> a "Can't contact LDAP server" error. The postgres error log contains:

You really shouldn't be using LDAP in an AD environment for
authentication- configure and use Kerberos instead, which is much more
secure than having cleartext passwords seen by the PG server and then
proxied to the LDAP server.

That said, there does appear to be an issue here, thanks for creating a
test case.

Stephen

Attachment

pgsql-bugs by date:

Previous
From: Huong Dangminh
Date:
Subject: power() function in Windows: "value out of range: underflow"
Next
From: Euler Taveira
Date:
Subject: Re: power() function in Windows: "value out of range: underflow"