Re: [HACKERS] Solaris ident authentication using unix domain sockets - Mailing list pgsql-patches

From Josh Berkus
Subject Re: [HACKERS] Solaris ident authentication using unix domain sockets
Date
Msg-id 4874FB8C.9090701@agliodbs.com
Whole thread Raw
In response to Re: [HACKERS] Solaris ident authentication using unix domain sockets  ("Florian G. Pflug" <fgp@phlo.org>)
List pgsql-patches
Florian,

> I'd be *very* interested in how they come to that assessment. I'd have
> thought that the only alternative to getpeereid/getupeercred is
> password-based or certificate-based authenticated - which seem *less*
> secure because a) they also rely on the client having the correct uid
> or gid (to read the password/private key), plus b) the risk of the
> password/private key getting into the wrong hands.

*shrug* don't ask me.  I don't agree with the policy, I can hardly
defend it.

--Josh

pgsql-patches by date:

Previous
From: Zdenek Kotala
Date:
Subject: Re: page macros cleanup (ver 04)
Next
From: Neil Conway
Date:
Subject: Re: [HACKERS] GIN improvements