RE: pg_hba.conf "authentication file token too long, skipping" - Mailing list pgsql-bugs

From Zechman, Derek S
Subject RE: pg_hba.conf "authentication file token too long, skipping"
Date
Msg-id PH0PR04MB8294A7C60AD0693E13E76671C00AA@PH0PR04MB8294.namprd04.prod.outlook.com
Whole thread Raw
In response to Re: pg_hba.conf "authentication file token too long, skipping"  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: pg_hba.conf "authentication file token too long, skipping"
List pgsql-bugs
" A one-line improvement would be to increase that constant, but it doesn't look very much harder to get rid of that
fixed-sizebuffer altogether in favor of a StringInfo." 

Is this something that can be included in the next patch?

-----Original Message-----
From: Tom Lane <tgl@sss.pgh.pa.us>
Sent: Monday, July 24, 2023 12:52 PM
To: Zechman, Derek S <Derek.S.Zechman@snapon.com>
Cc: pgsql-bugs@lists.postgresql.org
Subject: Re: pg_hba.conf "authentication file token too long, skipping"

CAUTION: This email originated from outside of Snap-on. Do not click on links or open attachments unless you have
validatedthe sender, even if it is a known contact. Contact the sender by phone to validate the contents. 

"Zechman, Derek S" <Derek.S.Zechman@snapon.com> writes:
> hostssl all +fnc_personal_account_rl XXX.XX.X.X/16 ldap ldapserver=xxxx-xxxx-xx-xx.mydomainname.com
ldapbasedn="OU=Users,OU=Primary,OU=All,DC=mydomainname,DC=com"
ldapbinddn="CN=abc_postgres_sa,OU=T1-ServiceAccounts,OU=Tier1,OU=Admin,OU=All,DC=mydomainname,DC=com"
ldapbindpasswd="30characterpassword"
ldapsearchfilter="(&(objectClass=user)(sAMAccountName=$username)(|(memberof=CN=xxx,OU=Groups,OU=Primary,OU=All,DC=mydomainname,DC=com)(memberof=CN=XxxxxxXXXx,OU=Groups,OU=Primary,OU=All,DC=mydomainname,DC=com)(memberof=CN=xxxxxxxxxxxxxx,OU=Groups,OU=Primary,OU=All,DC=mydomainname,DC=com)))"

Yeah, your ldapsearchfilter option is hitting the 256-byte MAX_TOKEN limit in hba.c.  A one-line improvement would be
toincrease that constant, but it doesn't look very much harder to get rid of that fixed-size buffer altogether in favor
ofa StringInfo. 

                        regards, tom lane



pgsql-bugs by date:

Previous
From: PG Bug reporting form
Date:
Subject: BUG #18045: NpgSQL installation not working
Next
From: PG Bug reporting form
Date:
Subject: BUG #18046: stats collection behaviour change is affecting the usability of information.