Managing LDAP User permissions - Mailing list pgsql-admin

From Wetmore, Matthew (CTR)
Subject Managing LDAP User permissions
Date
Msg-id e8a53062f73b47fb844075acda331c0a@express-scripts.com
Whole thread Raw
In response to Managing LDAP User permissions  (sbob <sbob@quadratum-braccas.com>)
Responses Re: Managing LDAP User permissions
List pgsql-admin
Removing user from ldap config will not remove from PG.

As Far As Best Practices, I have always Expired the password in PG and comment on that employee left.  We still leave
theuser intact (with expired psswd) for any audit need.
 
Expiring the psswd also gives you an exact timestamp in the db when they were denied db access.

-----Original Message-----
From: sbob <sbob@quadratum-braccas.com> 
Sent: Thursday, July 20, 2023 7:53 AM
To: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Subject: [EXTERNAL] Managing LDAP User permissions

All;


I know from the docs I can deploy LDAP authentication, one we do this how do we manage permissions within the database
foevarious LDAP users? 
 
Can I setup automatic permissions based on LDAP groups?

Can we ensure that if an employee leaves then these permissions are automatically removed?


Is there a best practice for this?


Thanks in advance





pgsql-admin by date:

Previous
From: Scott Ribe
Date:
Subject: Re: Upgrade from PG12 to PG
Next
From: M Sarwar
Date:
Subject: Re: Managing LDAP User permissions