Skip site navigation (1) Skip section navigation (2)

Re: protecting database from internet access

From: "codeWarrior" <gpatnude(at)hotmail(dot)com>
To: pgsql-admin(at)postgresql(dot)org
Subject: Re: protecting database from internet access
Date: 2005-10-12 15:13:31
Message-ID: dij95r$1a41$1@news.hub.org (view raw or flat)
Thread:
Lists: pgsql-admin
  From the postgreSQL docs:
16.7. Secure TCP/IP Connections with SSL
19.1. The pg_hba.conf file
  19.2. Authentication methods
    19.2.1. Trust authentication
    19.2.2. Password authentication
    19.2.3. Kerberos authentication
    19.2.4. Ident-based authentication
    19.2.5. PAM Authentication
  19.3. Authentication problems

""ashish srivastava"" <ashu_shri(at)hotmail(dot)com> wrote in message 
news:BAY111-F137A8BA63A48E213E01AF59F7B0(at)phx(dot)gbl(dot)(dot)(dot)
> hi,
>
> please do the needful..
>
> I am using j2ee on the server side and postgresql as the database to 
> connect. This database is exposed to the internet.
>
> The user is shown a login page in which user enters its username and 
> password. Password authentication takes place.This password is 
> authenticated on the basis of password field in the userprofile table.
>
> some questions :-
> 1)can anybody tell me how to do this so that the database is at most 
> secure on the internet ?
> 2)should i have different password(login password) for the connection 
> string ? or connection string password should be same and authentication 
> should be done by fetching the password value from the userprofile table 
> for the coressponding user ?
> 3)Encrypting the password ?
> 4)Adding the password in the session so that once authentication is done 
> user is allowed for authorization for different resources such 
> databases,tables etc..
> 5)providing some SSl or tunneling to the database ?
>
> please help with some examples..
>
> i am presently using pg admin III on windows of postgresql. later on might 
> switch to linux.
>
> i have read about pg_hba.conf file..But these things are not clear to me.
>
> Thanks,
> Ashish
>
> _________________________________________________________________
> Finding it difficult to find your life partner?Here is your solution 
> http://www.bharatmatrimony.com/ 
> http://creative.mediaturf.net/creatives/bm05/bm_msn_tagoffline.htm
>
>
> ---------------------------(end of broadcast)---------------------------
> TIP 5: don't forget to increase your free space map settings
> 



In response to

Responses

pgsql-admin by date

Next:From: David BearDate: 2005-10-12 17:11:02
Subject: front end application
Previous:From: Nigel BishopDate: 2005-10-12 14:15:37
Subject: DB cluster hanging

Privacy Policy | About PostgreSQL
Copyright © 1996-2014 The PostgreSQL Global Development Group