Re: SELinux context of PostgreSQL connection process

From: John R Pierce <pierce(at)hogranch(dot)com>
To: pgsql-general(at)postgresql(dot)org
Subject: Re: SELinux context of PostgreSQL connection process
Date: 2015-03-24 18:08:47
Message-ID: 5511A82F.406@hogranch.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On 3/24/2015 5:16 AM, Мартынов Александр wrote:
> There is postgres db with sepgsql enabled. When user connect to postgres db with psql, postgres create new process for each connection. These processes have selinux context unconfined_u:unconfined_r:postgresql_t.
>
> Is there a way to assign the process a context of user that connected to db?

what if that user is on a different system connecting over the network?

no, the only user the postgres server processes should run as are those
of the postgres server itself as it needs to read and write files in the
postgres data directory tree.

--
john, recycling bits in santa cruz

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Bankim Bhavsar 2015-03-24 18:49:14 Index corruption
Previous Message Saimon 2015-03-24 16:10:35 Re: How to distinguish serialization errors from others using pqxx