Re: pg_hba.conf: samehost and samenet [REVIEW]

From: Mark Mielke <mark(at)mark(dot)mielke(dot)cc>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Andrew Dunstan <andrew(at)dunslane(dot)net>, stef(at)memberwebs(dot)com, Robert Haas <robertmhaas(at)gmail(dot)com>, Magnus Hagander <magnus(at)hagander(dot)net>, Abhijit Menon-Sen <ams(at)toroid(dot)org>, pgsql-hackers <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: pg_hba.conf: samehost and samenet [REVIEW]
Date: 2009-09-23 21:49:55
Message-ID: 4ABA9803.1090303@mark.mielke.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 09/23/2009 05:40 PM, Tom Lane wrote:
>> I haven't looked at this "feature" at all, but I'd be inclined, on the
>> grounds you quite reasonably cite, to require a netmask with "samenet",
>> rather than just ask the interface for its netmask.
>>
> I was just thinking the same thing. Could we then unify samehost and
> samenet into one thing? sameaddr/24 or something like that, with
> samehost just being the limiting case of all bits used. I am not
> sure though if this works nicely for IPv6 as well as IPv4.

I could see some people wanting this as well - but it's not a
replacement for samenet, it would be an additional feature. For example,
at my company, I have a cluster of machines on a /26 subnet, but for
some accesses, I would prefer to "open it up" to /8, since our company
has a /8, and I may want to allow anybody in the company to connect,
regardless of how things are routed.

I may still want samenet in the same configuration, to grant additional
access if the person happens to be on my switch compared to "anywhere in
the company". For my switch, having to hard code the subnet is back to
being a pain. If we enlarge our subnet to /25, it's one more thing that
I would have to remember to change unnecessarily.

Cheers,
mark

--
Mark Mielke<mark(at)mielke(dot)cc>

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message daveg 2009-09-23 22:04:20 Re: Adding \ev view editor?
Previous Message Tom Lane 2009-09-23 21:48:52 Re: pg_hba.conf: samehost and samenet [REVIEW]