Re: local security - Mailing list pgsql-general

From Peter Eisentraut
Subject Re: local security
Date
Msg-id Pine.LNX.4.30.0104140335360.945-100000@peter.localdomain
Whole thread Raw
In response to local security  ("David M. Kaplan" <dkaplan@genes.bio.puc.cl>)
List pgsql-general
David M. Kaplan writes:

> I have a very simple security setup wish.  I only want to allow local
> connections where each user can only log into postgres as himself, but
> there isnt a "ident sameuser" option for local connections.  Is there
> any way around this?  Can anyone explain to me why such an option doesnt
> exist for local connections?

Because ident works based on TCP ports.  There is a similar mechanism for
Unix domain sockets implemented in some kernels, but it's not portable and
therefore there hasn't been wide-spread enthusiasm for supporting it.

--
Peter Eisentraut      peter_e@gmx.net       http://yi.org/peter-e/


pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: local security
Next
From: Karl DeBisschop
Date:
Subject: Re: anti Christian bias?