Skip site navigation (1) Skip section navigation (2)

Secure DB Systems - How to

From: "Sarah Tanembaum" <sarahtanembaum(at)yahoo(dot)com>
To: pgadmin-support(at)postgresql(dot)org
Cc: pgsql-admin(at)postgresql(dot)org, pgsql-hackers-win32(at)postgresql(dot)org,pgsql-php(at)postgresql(dot)org, pgsql-sql(at)postgresql(dot)org
Subject: Secure DB Systems - How to
Date: 2004-07-08 15:49:36
Message-ID: ccjra4$pgl$1@sea.gmane.org (view raw or flat)
Thread:
Lists: pgadmin-supportpgsql-adminpgsql-hackers-win32pgsql-phppgsql-sql
I was wondering if it is possible to create a secure database system
usingPostgreSQL/PHP combination?

I have the following in mind:

I wanted to store all my( and my brothers and sisters) important document
information such as birth certificate, SSN, passport number, travel
documents, insurance(car, home, etc) document, and other important documents
imagined in the database.

The data will be entered either manually and/or scanned(with OCR). I need to
be able to search on all the fields in the database.

We have 10 computers(5bros, 4sisters, and myself) plus 1 server with I
maintained. The data should be synchronize/replicate between those
computers.

Well, so far it is easy, isn't it?

Here's my question:

a) How can I make sure that it secure so only authorized person can
modify/add/delete the information? Beside transaction logs, are there any
other method to trace any transaction(kind of paper trail)?

Assuming there are 3 step process to one enter the info e.g:
- One who enter the info (me)
- One who verify the info(the owner of info)
- One who verify and then commit the change!
How can I implement such a process in PostgreSQL and/or PHP or any other web
language?

b) How can I make sure that no one can tap the info while we are entering
the data in the computer? (our family are scattered within US and Canada)

c) Is it possible to securely synchronize/replicate between our computers
using VPN? Does PostgreSQL has this functionality by default?

d) Other secure method that I have not yet mentioned.

Anyone has good ideas on how to implement such a systems?

Thanks







Responses

pgsql-php by date

Next:From: Elijah O. AlcantaraDate: 2004-07-09 02:39:28
Subject: wouldn't insert
Previous:From: Martin MarquesDate: 2004-07-07 19:52:43
Subject: Re: Warning: pg_fetch_row(): ...

pgsql-admin by date

Next:From: Mike RylanderDate: 2004-07-08 15:55:31
Subject: Re: cross databases?
Previous:From: Hilary ForbesDate: 2004-07-08 15:46:27
Subject: Re: cross databases?

pgadmin-support by date

Next:From: Bruno Wolff IIIDate: 2004-07-09 15:27:22
Subject: Re: [PHP] Secure DB Systems - How to
Previous:From: Keith C. PerryDate: 2004-07-07 18:29:55
Subject: Re: FYI: "clear window" function not working

pgsql-hackers-win32 by date

Next:From: Sarah TanembaumDate: 2004-07-08 16:28:34
Subject: Re: PgSQL not as Administrator - probs on windows
Previous:From: Tony and Bryn ReinaDate: 2004-07-08 14:21:45
Subject: Re: Finding zlib on MinGW

pgsql-sql by date

Next:From: Együd CsabaDate: 2004-07-09 05:15:13
Subject: Re: Constraint->function dependency and dump in 7.3
Previous:From: Pedro B.Date: 2004-07-08 13:36:37
Subject: Newbie (to postgres) question

Privacy Policy | About PostgreSQL
Copyright © 1996-2014 The PostgreSQL Global Development Group