Re: Authentication?

From: Bjørn T Johansen <btj(at)havleik(dot)no>
To: Stephen Frost <sfrost(at)snowman(dot)net>
Cc: "pgsql-general(at)lists(dot)postgresql(dot)org" <pgsql-general(at)lists(dot)postgresql(dot)org>
Subject: Re: Authentication?
Date: 2018-03-09 08:25:05
Message-ID: 20180309092505.28f50377@pennywise-btj.brreg.no
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Wed, 7 Mar 2018 10:19:35 -0500
Stephen Frost <sfrost(at)snowman(dot)net> wrote:

> Greetings,
>
> * Bjørn T Johansen (btj(at)havleik(dot)no) wrote:
> > Is it possible to use one authentication method as default, like LDAP, and if the user is not found, then try to authenticate using
> > md5/scram-sha-256 ?
>
> Not directly in pg_hba.conf. You might be able to construct a system
> which works like this using PAM though, but it wouldn't be much fun.
>
> LDAP use really should be discouraged as it involves sending the
> password to the PG server. If you are operating in an active directory
> environment then you should be using GSSAPI/Kerberos.
>
> SCRAM is a good alternative as it doesn't send the password to the
> server either, though that is only available in PG10, of course.
>
> Thanks!
>
> Stephen

Ok, thx... Will check out GSSAPI/Kerberos instead... :)

BTJ

In response to

Browse pgsql-general by date

  From Date Subject
Next Message wolfgang 2018-03-09 08:52:26 pg/tcl performance related
Previous Message Jan Bilek 2018-03-08 22:55:29 RE: Troubleshooting a segfault and instance crash