Re: Disable /Suppress hostname checks while secured LDAP

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Sathesh S <sathesh(dot)sundaram(at)hotmail(dot)com>
Cc: "pgsql-admin(at)postgresql(dot)org" <pgsql-admin(at)postgresql(dot)org>
Subject: Re: Disable /Suppress hostname checks while secured LDAP
Date: 2018-02-14 14:21:06
Message-ID: 20180214142106.GA2416@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Greetings,

* Sathesh S (sathesh(dot)sundaram(at)hotmail(dot)com) wrote:
> Is there a way to disable/suppress hostname checks in while using Secured LDAP in postgreSQL for authentication.
>
> The issue what we have is that the LDAP certificate what we are using is working for fully qualified named of the domain but not when we use a direct LDAP server in the pg_ba.conf file.
>
> For example:
> This works - ldapserver="ldaps//dummy.company.com"
>
> This doesnt work - ldapserver="server1.dummy.company.com"
>
> Our internal LDAP team says that we nees to disable/suppress the hostname checking on the postgreSQL side for the 2nd option to work.
>
> Does anyone have an idea on how we can suppress hostnames check while using Secured LDAP.

This really isn't recommended because the point of the hostname check is
to verify that you're actually talking to the server you intended to.

What LDAP server are you using though..? If this is in an Active
Directory environment, or any environment where you have Kerberos
available, then you should be using Kerberos and *not* using LDAP (or
even LDAPS) for authentication as it isn't nearly as secure.

Thanks!

Stephen

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Stephen Frost 2018-02-14 14:25:11 Re: Calculation of Database Size in postgres
Previous Message pavan95 2018-02-14 12:21:16 Re: Calculation of Database Size in postgres