Skip site navigation (1) Skip section navigation (2)

Re: Thoughts on the location of configuration files

From: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Peter Eisentraut <peter_e(at)gmx(dot)net>, PostgreSQL Development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Thoughts on the location of configuration files
Date: 2001-12-24 03:49:38
Message-ID: 200112240349.fBO3nc927006@candle.pha.pa.us (view raw or flat)
Thread:
Lists: pgsql-hackers
> Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> writes:
> > Well, the problem with backward compatibility here is that now we have
> > pg_hba.conf to configure some part of local authentication and
> > postgresql.conf to configure the other part.
> 
> Seems a pretty empty argument.  pg_ident.conf also (now) bears on local
> authentication, as does any random secondary-password file the user
> might select.  Shall we find a way to smush all that into pg_hba.conf?
> 
> > Aren't the socket permissions best dealt with in pg_hba.conf?
> 
> Maybe if we were designing the whole thing from scratch, it'd be cleaner
> to do it that way ... but it doesn't seem enough cleaner to justify
> creating a compatibility issue.

How many people really use unix socket permissions in postgresql.conf?
Probably very few.  We could announce when it goes away, and even throw
an error if it appears in postgresql.conf.  Seems that would clear it up
and make the feature much more usable.

Security is very easy to mess up.  That's why I think clarity is
important.  If we are going to change the default socket permissions to
700, that clearly would be a good time to make the change, no?

-- 
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman(at)candle(dot)pha(dot)pa(dot)us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026

In response to

Responses

pgsql-hackers by date

Next:From: Tom LaneDate: 2001-12-24 04:06:30
Subject: Re: Announcement: libpkixpq 0.1 released
Previous:From: Tom LaneDate: 2001-12-24 03:43:59
Subject: Re: Thoughts on the location of configuration files

Privacy Policy | About PostgreSQL
Copyright © 1996-2014 The PostgreSQL Global Development Group