Re: [HACKERS] Is "trust" really a good default?

From: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
To: Magnus Hagander <mha(at)sollentuna(dot)net>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, pgsql-hackers(at)postgresql(dot)org, pgsql-patches(at)postgresql(dot)org
Subject: Re: [HACKERS] Is "trust" really a good default?
Date: 2004-07-13 21:42:57
Message-ID: 200407132142.i6DLgvp02805@candle.pha.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-patches

Magnus Hagander wrote:
> >>> The only part of this discussion that I'd really be prepared=20
> >>> to buy into
> >>> is the part about *if* you use -W or --pwfile, then set up
> >pg_hba.conf
> >>> with MD5 as the default auth (because that's probably what the user
> >>> wants anyway).
> >
> >> Ok. Here is a patch that does this.
> >
> >... and rather severely mangles the comments, too;
>
> Um, no, it doesn't. At least not on my installation.
>
>
> > not to mention the
> >more basic problem that the comments will now be wrong.
>
> That, however, it is correct :-( Sloppy.
>
> How about a text along the line of:
> CAUTION: Configuring the system for "trust" authentication allows any
> local user to connect using any PostgreSQL user name, including the
> superuser, over either Unix domain sockets or TCP/IP. If you are on
> a multiple-user machine, this is probably not good. Change it to use
> something other than "trust" authentication.

New wording:

CAUTION: Configuring the system for local "trust" authentication allows
any local user to connect as any PostgreSQL user, including the database
superuser. If you do not trust all your local users, use another
authenication method.

--
Bruce Momjian | http://candle.pha.pa.us
pgman(at)candle(dot)pha(dot)pa(dot)us | (610) 359-1001
+ If your life is a hard drive, | 13 Roberts Road
+ Christ can be your backup. | Newtown Square, Pennsylvania 19073

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Mike Benoit 2004-07-13 21:44:11 Re: Release planning (was: Re: Status report)
Previous Message Lamar Owen 2004-07-13 21:40:14 Re: Release planning (was: Re: Status report)

Browse pgsql-patches by date

  From Date Subject
Next Message Bruce Momjian 2004-07-13 21:44:19 Re: [HACKERS] Is "trust" really a good default?
Previous Message Tom Lane 2004-07-13 21:36:46 Re: serverlog rotation/functions