What goes into the security doc?

From: Dan Langille <dan(at)langille(dot)org>
To: pgsql-hackers(at)postgresql(dot)org
Cc: dan(at)langille(dot)org
Subject: What goes into the security doc?
Date: 2003-01-20 05:01:12
Message-ID: 20030119234411.S76103-100000@m20.unixathome.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-docs pgsql-hackers

With reference to my post to the "PostgreSQL Password Cracker" on
2003-01-02, I've promised to write a security document for the project.
Here it is, Sunday night, and I can't sleep. What better way to get there
than start this task...

My plan is to write this in very simple HTML. I will post the draft
document on my website and post the URL here from time to time for
feedback. Please make suggestions for content. So far, I will cover these
items:

- .pgpass (see
http://developer.postgresql.org/docs/postgres/libpq-files.html)
- local connections
- remote connections (recommending SSL)
- pg_hba (only in passing, most of that is at
http://www.postgresql.org/idocs/index.php?client-authentication.html)
- running the postmaster as a specific user

That doesn't sound like much. Surely you can think of something else to
add. Should I post this to another list for their views?

OK, that's done it. I'm ready for sleep now.

Responses

Browse pgsql-docs by date

  From Date Subject
Next Message Robert Treat 2003-01-21 15:16:31 Re: What goes into the security doc?
Previous Message Laszlo Hornyak 2003-01-17 14:23:20 hungarian FAQ translation update

Browse pgsql-hackers by date

  From Date Subject
Next Message Bruno Wolff III 2003-01-20 06:09:09 Re: Getting float8 data into cube?
Previous Message postgresql 2003-01-20 04:52:52