Re: hba conf ident sameuser not working

From: David Bear <David(dot)Bear(at)asu(dot)edu>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: David(dot)Bear(at)asu(dot)edu, Peter Eisentraut <peter_e(at)gmx(dot)net>, pgsql-admin(at)postgresql(dot)org
Subject: Re: hba conf ident sameuser not working
Date: 2006-02-16 17:26:21
Message-ID: 20060216172621.GB15469@asu.edu
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

On Wed, Feb 15, 2006 at 09:00:41PM -0500, Tom Lane wrote:
> David Bear <David(dot)Bear(at)asu(dot)edu> writes:
> > now, back on teancum that has the tunnel on port 6666, I do this:
>
> > iddwb(at)teancum:~> psql -p 6666 -h localhost -U tlhowell
> > psql: FATAL: Ident authentication failed for user "tlhowell"
> > iddwb(at)teancum:~> psql -p 6666 -h localhost -U iddwb
> > psql: FATAL: Ident authentication failed for user "iddwb"
>
> I'm afraid you're kind of stuck on getting that to work. In the cases
> that work, psql is executing on the server side of the ssh connection.
> Here, you want it to work on the client side. The problem is that the
> Postgres server is going to see that TCP connection as originating from
> a server-side sshd daemon process, and so ident is quite properly going
> to fail unless the requested database username matches whatever sshd is
> running as.
>
> You could possibly get it to work if you could get sshd to run the
> daemon subprocess as yourself instead of root ... dunno enough about
> ssh to know if that's possible.

thats the path I was thinking along... Thanks.

>
> regards, tom lane
>
> ---------------------------(end of broadcast)---------------------------
> TIP 6: explain analyze is your friend

--
David Bear
phone: 480-965-8257
fax: 480-965-9189
College of Public Programs/ASU
Wilson Hall 232
Tempe, AZ 85287-0803
"Beware the IP portfolio, everyone will be suspect of trespassing"

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Barry Moore 2006-02-16 18:23:21 Trouble starting server
Previous Message Jerry Sievers 2006-02-16 17:14:29 Re: Dropping of indexes with cached PL query plans