security issues - Mailing list pgsql-admin

From Andreas Muck
Subject security issues
Date
Msg-id m390lk4j5n.fsf@koala.rhein-neckar.de
Whole thread Raw
List pgsql-admin
Hello

seems like my mail to pgsql-novice is being ignored so I'll try here.

How can I let local users connect with their own ID locally without
having to enter a password, but disallow them to reconnect - with
\connect - as another user - either completely or allow it only using
a password.

Right now everybody connected localy can use "\connect database
postgres" and become the postgres super-user (or any other user).

Second question: how can I prevent users from creating tables in other
databases beside their own (or a set of specified databases). Something
like `grant create table on database to somebody'.

Using PostreSQL 6.3.2 on Linux.

tia,
Andi

PS: A pointer to the documentation is also welcome, I couldn't find it
anywhere.

pgsql-admin by date:

Previous
From: "Matthew J. Farrenkopf"
Date:
Subject: Problems with regression tests
Next
From: dongrami@mail.hitel.net
Date:
Subject: .