Re: Authentication?

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Bjørn T Johansen <btj(at)havleik(dot)no>
Cc: "pgsql-general(at)lists(dot)postgresql(dot)org" <pgsql-general(at)lists(dot)postgresql(dot)org>
Subject: Re: Authentication?
Date: 2018-03-07 15:19:35
Message-ID: 20180307151934.GH2416@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

Greetings,

* Bjørn T Johansen (btj(at)havleik(dot)no) wrote:
> Is it possible to use one authentication method as default, like LDAP, and if the user is not found, then try to authenticate using
> md5/scram-sha-256 ?

Not directly in pg_hba.conf. You might be able to construct a system
which works like this using PAM though, but it wouldn't be much fun.

LDAP use really should be discouraged as it involves sending the
password to the PG server. If you are operating in an active directory
environment then you should be using GSSAPI/Kerberos.

SCRAM is a good alternative as it doesn't send the password to the
server either, though that is only available in PG10, of course.

Thanks!

Stephen

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Scott Frazer 2018-03-07 15:21:51 Re: Help troubleshooting SubtransControlLock problems
Previous Message David G. Johnston 2018-03-07 15:19:14 Re: Authentication?