From: | Rajesh Kumar Mallah <mallah(at)trade-india(dot)com> |
---|---|
To: | Sarah Tanembaum <sarahtanembaum(at)yahoo(dot)com> |
Cc: | pgsql-sql(at)postgresql(dot)org |
Subject: | Re: Secure DB Systems - How to |
Date: | 2004-07-12 14:07:21 |
Message-ID: | 40F29B19.2020407@trade-india.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgadmin-support pgsql-admin pgsql-hackers-win32 pgsql-php pgsql-sql |
Sarah Tanembaum wrote:
>I was wondering if it is possible to create a secure database system
>usingPostgreSQL/PHP combination?
>
>I have the following in mind:
>
>I wanted to store all my( and my brothers and sisters) important document
>information such as birth certificate, SSN, passport number, travel
>documents, insurance(car, home, etc) document, and other important documents
>imagined in the database.
>
>The data will be entered either manually and/or scanned(with OCR). I need to
>be able to search on all the fields in the database.
>
>We have 10 computers(5bros, 4sisters, and myself) plus 1 server with I
>maintained. The data should be synchronize/replicate between those
>computers.
>
>Well, so far it is easy, isn't it?
>
>Here's my question:
>
>a) How can I make sure that it secure so only authorized person can
>modify/add/delete the information? Beside transaction logs, are there any
>other method to trace any transaction(kind of paper trail)?
>
>
There can be multiple solutions to your problem.
The security and logging may be implemented either at
database level or application level. That is a call you have to
take.
If you consider the database to take care of security and logging
you could do the following.
1. create a database user for each of your family members
2. ask the memebers to login to your application using their own id.
3. Use that id for connecting to the database using php.
the security at table level can be managed by various GRANT commands.
the security at row level can be done using a mechanism methods
describe in the -general mailling list (search: "row level grants").
For logging changes to your tables you can create audit trail of all
the tables in question by using triggers or enbale logging of sql
statements (with current user display) in postgresql server.
u may consider:
http://gborg.postgresql.org/project/audittrail/projdisplay.php
although i have not used it myself.
>Assuming there are 3 step process to one enter the info e.g:
>- One who enter the info (me)
>- One who verify the info(the owner of info)
>- One who verify and then commit the change!
>How can I implement such a process in PostgreSQL and/or PHP or any other web
>language?
>
>
I think such a moderation should be implemented at application
level.
>b) How can I make sure that no one can tap the info while we are entering
>the data in the computer? (our family are scattered within US and Canada)
>
>
you may run yor web application using https:// rather than http://
and you may enable ssl in postgresql for securing the communication
between application and database.
>c) Is it possible to securely synchronize/replicate between our computers
>using VPN? Does PostgreSQL has this functionality by default?
>
>
Slony and many other replication solution exists for asyncronous
replication.
Hope it helps a bit.
Regds
Mallah.
>d) Other secure method that I have not yet mentioned.
>
>Anyone has good ideas on how to implement such a systems?
>
>Thanks
>
>
>
>
>
>
>
>---------------------------(end of broadcast)---------------------------
>TIP 8: explain analyze is your friend
>
>
>
--
regds
Mallah.
Rajesh Kumar Mallah
+---------------------------------------------------+
| Tradeindia.com (3,11,246) Registered Users |
| Indias' Leading B2B eMarketPlace |
| http://www.tradeindia.com/ |
+---------------------------------------------------+
From | Date | Subject | |
---|---|---|---|
Next Message | Sarah Tanembaum | 2004-07-12 21:48:34 | Re: [PHP] Secure DB Systems - How to |
Previous Message | Andreas Pflug | 2004-07-12 13:16:12 | Re: Bug report CHECK CONSTRAINTS |
From | Date | Subject | |
---|---|---|---|
Next Message | Markus Bertheau | 2004-07-12 15:08:38 | statistics collector: number of function calls |
Previous Message | Konstantin Pelepelin | 2004-07-12 09:26:41 | Re: are there ways for 'idle timeout'? |
From | Date | Subject | |
---|---|---|---|
Next Message | Giselle Dazzi | 2004-07-12 15:21:01 | PostGre and Windows XP |
Previous Message | Merlin Moncure | 2004-07-12 13:44:06 | Re: Finding zlib on MinGW |
From | Date | Subject | |
---|---|---|---|
Next Message | Scott Marlowe | 2004-07-12 14:46:35 | Re: Resource id #12 |
Previous Message | Christopher Kings-Lynne | 2004-07-12 08:18:08 | Re: Resource id #12 |
From | Date | Subject | |
---|---|---|---|
Next Message | Hilary Forbes | 2004-07-12 16:09:05 | Order of execution of rules |
Previous Message | Rajesh Kumar Mallah | 2004-07-12 14:06:03 | Re: Comparing tsearch2 vectors. |