Re: SSL over Unix-domain sockets - Mailing list pgsql-hackers

From Tom Lane
Subject Re: SSL over Unix-domain sockets
Date
Msg-id 23996.1200411992@sss.pgh.pa.us
Whole thread Raw
In response to Re: SSL over Unix-domain sockets  (Alvaro Herrera <alvherre@commandprompt.com>)
Responses Re: SSL over Unix-domain sockets  (Alvaro Herrera <alvherre@commandprompt.com>)
Re: SSL over Unix-domain sockets  (Greg Smith <gsmith@gregsmith.com>)
Re: SSL over Unix-domain sockets  (Alvaro Herrera <alvherre@commandprompt.com>)
List pgsql-hackers
Alvaro Herrera <alvherre@commandprompt.com> writes:
> Perhaps the easiest thing to do is to create a (possibly dangling)
> symlink in /tmp to the real socket in a protected dir.

Cute idea ...

> One thing to be aware of is /tmp cleaners ...

... but that would definitely be a problem.  I think on most systems
you'd have to explicitly tweak the /tmp-cleaning script to know not to
zap such a link.  Given that such a local customization would probably
disappear in your next system update, the security gain might be
fleeting.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Declarative partitioning grammar
Next
From: Markus Schiltknecht
Date:
Subject: Re: Declarative partitioning grammar