PosgreSQL Security Architecture

From: Lesley Kimmel <lesley(dot)j(dot)kimmel(at)gmail(dot)com>
To: pgsql-general(at)postgresql(dot)org
Subject: PosgreSQL Security Architecture
Date: 2016-02-11 16:30:41
Message-ID: CAAQu=7QM9rn+NgcthKdCaXx_bJ2UrqBNGTSfQtH+by1Yrh2-NA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

All;

I'm working to secure a PosgreSQL database according to a DoD security
guide. It has many very generic requirements that get more toward the
internal architecture of the system that wouldn't be apparent to the
average admin. I was hoping someone might have some insight to the
following requirements:

a) The DBMS must maintain the authenticity of communications sessions by
guarding against man-in-the-middle attacks that guess at Session ID values.

b) Check DBMS settings and vendor documentation to verify the DBMS properly
handles transactions in the event of a system failure. The consistent state
must include a security configuration that is at least as restrictive as
before the system failure. This must be guaranteed.

Thanks in advance,
-LJK

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Adrian Klaver 2016-02-11 16:41:59 Re: PosgreSQL Security Architecture
Previous Message Adrian Klaver 2016-02-11 16:20:38 Re: PostgreSQL vs Firebird SQL