Re: initdb recommendations

From: Noah Misch <noah(at)leadboat(dot)com>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>, PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>, "Jonathan S(dot) Katz" <jkatz(at)postgresql(dot)org>
Subject: Re: initdb recommendations
Date: 2019-05-24 15:23:57
Message-ID: 20190524152357.GC1624191@rfd.leadboat.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-docs pgsql-hackers

On Thu, May 23, 2019 at 06:56:49PM +0200, Magnus Hagander wrote:
> On Thu, May 23, 2019, 18:54 Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com> wrote:
> > To recap, the idea here was to change the default authentication methods
> > that initdb sets up, in place of "trust".
> >
> > I think the ideal scenario would be to use "peer" for local and some
> > appropriate password method (being discussed elsewhere) for host.
> >
> > Looking through the buildfarm, I gather that the only platforms that
> > don't support peer are Windows, AIX, and HP-UX. I think we can probably
> > figure out some fallback or alternative default for the latter two
> > platforms without anyone noticing. But what should the defaults be on
> > Windows? It doesn't have local sockets, so the lack of peer wouldn't
> > matter. But is it OK to default to a password method, or would that
> > upset people particularly?
>
> I'm sure password would be fine there. It's what "everybody else" does
> (well sqlserver also cord integrated security, but people are used to it).

Our sspi auth is a more-general version of peer auth, and it works over TCP.
It would be a simple matter of programming to support "peer" on Windows,
consisting of sspi auth with an implicit pg_ident map. Nonetheless, I agree
password would be fine.

In response to

Responses

Browse pgsql-docs by date

  From Date Subject
Next Message Liudmila Mantrova 2019-05-24 15:29:59 Google Season of Docs 2019 - exploration phase
Previous Message Jonathan S. Katz 2019-05-24 14:54:24 Re: initdb recommendations

Browse pgsql-hackers by date

  From Date Subject
Next Message Amit Khandekar 2019-05-24 15:30:36 Re: Minimal logical decoding on standbys
Previous Message Andres Freund 2019-05-24 15:22:38 Re: Teach pg_upgrade test to honor NO_TEMP_INSTALL