Re: How to revoke privileged from PostgreSQL's superuser - Mailing list pgsql-admin

From Bruce Momjian
Subject Re: How to revoke privileged from PostgreSQL's superuser
Date
Msg-id 20180814195919.GA29140@momjian.us
Whole thread Raw
In response to Re: How to revoke privileged from PostgreSQL's superuser  (Benedict Holland <benedict.m.holland@gmail.com>)
Responses Re: How to revoke privileged from PostgreSQL's superuser  (dangal <danielito.gallo@gmail.com>)
Re: How to revoke privileged from PostgreSQL's superuser  (Bruce Momjian <bruce@momjian.us>)
Re: How to revoke privileged from PostgreSQL's superuser  (Bruce Momjian <bruce@momjian.us>)
List pgsql-admin
On Fri, Aug 10, 2018 at 04:06:40PM -0400, Benedict Holland wrote:
> I also would take Bruce's comment with a massive grain of salt. Everything that
> everyone does on a database is logged somewhere assuming proper logging. Now do
> you have the person-power to go through gigs of plain text logs to find out if
> someone is doing something shady... that is a question for your management
> team. Also, if you suspect someone of doing something shady, you should
> probably revoke their admin rights. 

Agreed, the best way to limit the risk of undetected DBA removal of data
is secure auditing --- I should have mentioned that.

-- 
  Bruce Momjian  <bruce@momjian.us>        http://momjian.us
  EnterpriseDB                             http://enterprisedb.com

+ As you are, so once was I.  As I am, so you will be. +
+                      Ancient Roman grave inscription +


pgsql-admin by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: How to revoke privileged from PostgreSQL's superuser
Next
From: Bruce Momjian
Date:
Subject: Re: pg_upgrade failing with error pg_resetxlog no such file