Re: SE-PgSQL patch review

From: KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: jd(at)commandprompt(dot)com, David Fetter <david(at)fetter(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Itagaki Takahiro <itagaki(dot)takahiro(at)oss(dot)ntt(dot)co(dot)jp>, KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: SE-PgSQL patch review
Date: 2009-12-02 01:53:14
Message-ID: 4B15C88A.9010807@ak.jp.nec.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Tom Lane wrote:
> "Joshua D. Drake" <jd(at)commandprompt(dot)com> writes:
>> On Mon, 2009-11-30 at 20:28 -0800, David Fetter wrote:
>>> This is totally separate from the really important question of whether
>>> SE-Linux has a future, and another about whether, if SE-Linux has a
>>> future, PostgreSQL needs to go there.
>
>> Why would we think that it doesn't?
>
> Have you noticed anyone except Red Hat taking it seriously?
>
> I work for Red Hat and have drunk a reasonable amount of the SELinux
> koolaid, but I can't help observing that it's had very limited uptake
> outside Red Hat. It's not clear that there are many people who find
> it a cost-effective solution to their problems. As for the number of
> people prepared to write custom policy for it --- which would be
> required to use it effectively for almost any PG application ---
> I could probably hold a house party for all of them and not break a
> sweat serving drinks.

If you concerned about SELinux support may not drive explosive growth
in the number of PostgreSQL users, it is correct. It focuses on the
people who concerned about system security including RDBMS.
It is indeed a niche. All the people does not store their classified
information within databases. But, it is also a fact there are certain
demands, not limited to existing SELinux and PostgreSQL users.
("Synergetic effect" is a correct English expression?)

Now PostgreSQL has various kind of optional features. I think these are
not always valuable for all the people, but it is valuable for users who
enabled the features. SELinux support is not a special case.

Thanks,
--
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message KaiGai Kohei 2009-12-02 02:07:19 Re: SE-PgSQL patch review
Previous Message KaiGai Kohei 2009-12-02 01:52:20 Re: SE-PgSQL patch review