Re: pg_hba.conf alternative - Mailing list pgsql-hackers

From Tino Wildenhain
Subject Re: pg_hba.conf alternative
Date
Msg-id 43F040CA.2050209@wildenhain.de
Whole thread Raw
In response to Re: pg_hba.conf alternative  (Q Beukes <pgsql-dev@list.za.net>)
Responses Re: pg_hba.conf alternative
List pgsql-hackers
Q Beukes schrieb:
> how? is there some kernel patch to completely to enable you to deny
> access to root?
> Tino Wildenhain pointed out SELinux has a feature like that.

I still dont get your problem (apart from that you can always
google for SELinux)

Why arent the other "admins" not trustworthy? And why do you
have many of them? If they only check logs and create users,
why do they have to be admins? They could use carefully
configured sudo as well to fullfill their tasks w/o full
access to the system.

I'd say, grep your problem at the root (literally spoken)

Regards
Tino


pgsql-hackers by date:

Previous
From: Q Beukes
Date:
Subject: Re: pg_hba.conf alternative
Next
From: Rick Gigger
Date:
Subject: Re: pg_hba.conf alternative