Re: Information of pg_stat_ssl visible to all users

From: Peter Eisentraut <peter_e(at)gmx(dot)net>
To: Magnus Hagander <magnus(at)hagander(dot)net>, Michael Paquier <michael(dot)paquier(at)gmail(dot)com>
Cc: PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Information of pg_stat_ssl visible to all users
Date: 2015-07-02 15:40:05
Message-ID: 55955B55.9050705@gmx.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 6/10/15 2:17 AM, Magnus Hagander wrote:
> AIUI that one was just about the DN field, and not about the rest. If I
> understand you correctly, you are referring to the whole thing, not just
> one field?

I think at least the DN field shouldn't be visible to unprivileged users.

Actually, I think the whole view shouldn't be accessible to unprivileged
users, except maybe your own row.

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Andrew Dunstan 2015-07-02 15:41:36 Re: raw output from copy
Previous Message Sawada Masahiko 2015-07-02 15:30:07 Re: Freeze avoidance of very large table.