Re: pam auth - add rhost item

From: Euler Taveira <euler(at)timbira(dot)com(dot)br>
To: kolo hhmow <grzsmp(at)gmail(dot)com>
Cc: Robert Haas <robertmhaas(at)gmail(dot)com>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: pam auth - add rhost item
Date: 2015-10-16 12:47:01
Message-ID: 5620F1C5.7020201@timbira.com.br
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 15-10-2015 05:41, kolo hhmow wrote:
> I have already explained this in my previous post. Did you read this?
>
Yes, I do.

> So why postgresql give users an abbility to use a pam modules, when in
> other side there is advice to not use them?
> Anyway.
>
Where is such advise? I can't see it in docs [1].

> I do not see any complication with this approach. Just use one
> configuration entry in pg_hba.conf, and rest entries in some database
> backend of pam module, which is most convenient with lot of entries than
> editing pg_hba.conf.
>
Why don't you use a group role? I need just one entry in pg_hba.conf.

[1] http://www.postgresql.org/docs/current/static/auth-methods.html#AUTH-PAM
[2] http://www.postgresql.org/docs/current/static/role-membership.html

--
Euler Taveira Timbira - http://www.timbira.com.br/
PostgreSQL: Consultoria, Desenvolvimento, Suporte 24x7 e Treinamento

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Glenn Zhu 2015-10-16 13:03:34 Error creating gin index on jsonb columns
Previous Message Robert Haas 2015-10-16 12:03:11 Re: Parallel Seq Scan