On 9/19/2017 12:33 PM, chiru r wrote:
> Yes, LDAP will do. However we need to sync the user accounts and
> groups between AD and PG servers.and then AD profiles will apply to
> PG user accounts for authentication.
>
if you're using LDAP from the AD servers to authenticate, whats to sync?
my database servers, the only 'users' connecting to them directly are
the database administrators... the applications connect with
application accounts, and if more security is required, these use
certificates, or they use unix 'ident' local connections.
--
john r pierce, recycling bits in santa cruz