Re: Authentication method for web app

From: "Jonathan Tripathy" <jonnyt(at)abpni(dot)co(dot)uk>
To: <pgsql-general(at)postgresql(dot)org>
Subject: Re: Authentication method for web app
Date: 2010-05-14 13:26:39
Message-ID: 46C13AA90DB8844DAB79680243857F0F061FAD@server1.ABPNI.local
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

________________________________

From: pgsql-general-owner(at)postgresql(dot)org on behalf of Leonardo F
Sent: Fri 14/05/2010 14:24
To: pgsql-general(at)postgresql(dot)org
Subject: Re: [GENERAL] Authentication method for web app

>I think this point number 2 is pretty important. If at all possible, keep
> the webapp separate from the database, and keep the database
> server on a fairly restrictive firewall. This means that someone has
> got to get in to the webapp, then hop to the database server, it just
> adds another layer of mis-direction for any would-be evil doers.

Which are the authentication methods "recommended" in this
scenario? It sounds to me that no matter the auth mechanism,
if a user can connect to the webapp server with the user that runs
the webapp there's no way of avoiding the connection to the db
(since the user will then be free to see/do whatever the webapp was
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Here is my 2 pence:

There are 2 types of security in computer. Physical and non-physical.

You are correct in saying that if someone were to get the user credentials of the user that the web app runs under, then they could access nearly everything that the web app could see. You then have to decide how to protect those credentials. Your web app should never disclose them, and a person should not give them out.

Bottom line, secure your server physicall, as well as logically. Don't give the web app users password out, don't give it a login shell etc..etc..

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Marc G. Fournier 2010-05-14 13:39:06 Re: List traffic
Previous Message Leonardo F 2010-05-14 13:24:38 Re: Authentication method for web app