agora inbox for postgres@postgres.berkeley.edu  
help / color / mirror / Atom feed
From: Paul M. Aoki <aoki@postgres.Berkeley.EDU>
To: Egan F. Ford <egan@cbs.cis.com>
Cc: Postgres Mailing List <postgres@postgres.Berkeley.EDU>
Subject: Re: new to postgres
Date: Tue, 03 May 94 16:58:12 -0700
Message-ID: <199405032358.QAA18961@faerie.CS.Berkeley.EDU> (raw)
In-Reply-To: <9405032105.AA19996@cbs.cis.com>

egan@cbs.cis.com (Egan F. Ford) writes:
> I've just installed postgres 4.2 on my linux box, it works great.  However I
> have data that my be secure.  Can anyone on the internet with a postgres
> client (e.g. monitor) access my database through post 4321?

correct.  this is documented in various places in the reference and
user manuals; if you want network authentication we do provide code 
to support either kerberos v4 or v5beta2 (it has not been tested with
v5beta3).

you can always do the reserved port thing.  this gives you as much
protection as rlogin/rsh, which is to say, very little (since any
moron can be superuser on their own machine).

it would not be rocket science to hack in a password scheme but in 
this new, unfriendly era of widespread network sniffing, password 
schemes are questionable security at best.

general note:
i know i'm behind on message traffic.  sorry.  things are in sort of
tizzy at berkeley right now.
--
  Paul M. Aoki  |  CS Div., Dept. of EECS, UCB  |  aoki@postgres.Berkeley.EDU
                |  Berkeley, CA 94720           |  ...!uunet!ucbvax!aoki

===============================================================================
    To add/remove yourself from the POSTGRES mailing list: send mail with 
    the subject line ADD or DEL to "postgres-request@postgres.Berkeley.EDU"

    If this fails, send mail to "post_questions@postgres.Berkeley.EDU" and
    a human will deal with it.  DO NOT post to the "postgres" mailing list.
===============================================================================




reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: postgres@postgres.berkeley.edu
  Cc: aoki@postgres.Berkeley.EDU, egan@cbs.cis.com
  Subject: Re: new to postgres
  In-Reply-To: <199405032358.QAA18961@faerie.CS.Berkeley.EDU>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox