From: | "Karl O(dot) Pinc" <kop(at)meme(dot)com> |
---|---|
To: | Együd Csaba <csegyud(at)vnet(dot)hu> |
Cc: | pgsql-general(at)postgresql(dot)org |
Subject: | Re: Making the DB secure |
Date: | 2005-06-20 18:50:39 |
Message-ID: | 1119293439l.5631l.3l@mofo |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-general |
On 06/20/2005 12:32:12 PM, Együd Csaba wrote:
> Hi,
> thank you very much. These are very good ideas, I think.
> I forgot one thing to mention. We will have very few clients (max. 20)
> and
> all clients will be required to have a fix IP address. Fix IP
> addresses can
> be listed in pg_hba.conf to filter incoming IPs very efficiently. With
> this
> note, do you think we need VPN or other enhancement?
You want to consider the failure modes. LANs can be
ARP spoofed to redirect traffic to elsewhere than their
destination IP, or what happens if the client does not request
encryption or the server is restarted without encryption
enabled, etc. You don't want to be allowing insecure
communication by accident and unawares. VPNs are
designed to disable communication
on failure, and the designers have presumably thought
of all the senarios. When you roll your own security
you need to be the one that thinks of everything.
(Of course, some VPN products are much less secure
than others.)
And maintaining things over time is always an issue.
Karl <kop(at)meme(dot)com>
Free Software: "You don't pay back, you pay forward."
-- Robert A. Heinlein
From | Date | Subject | |
---|---|---|---|
Next Message | Tom Lane | 2005-06-20 19:06:54 | Re: Why can't I install in a terminal session? |
Previous Message | Együd Csaba | 2005-06-20 18:45:48 | Re: Making the DB secure |