From: | Michael Ansley <Michael(dot)Ansley(at)intec-telecom-systems(dot)com> |
---|---|
To: | "'Thierry Besancon'" <Thierry(dot)Besancon(at)prism(dot)uvsq(dot)fr>, Tim Frank <tfrank(at)registrar(dot)uoguelph(dot)ca> |
Cc: | pgsql-admin(at)postgresql(dot)org |
Subject: | RE: Backing up postgresql databases |
Date: | 2001-03-20 11:48:08 |
Message-ID: | 7F124BC48D56D411812500D0B747251480F4C1@FILESERVER002 |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-admin |
Is there any reason why programs like this could not be given a simple
properties file which contains the username and password. This file could
then be passed on the command line, but nobody (other than, say, root, or
postgres) would have access to it at all. I've seen a number of systems use
this type of solution, and although it appears superficially useless (am I
opening myself to be shot down or what ;-), the security of the file system
creates (as far as I can see) reasonable safety.
Just my EUR25...
MikeA
>> -----Original Message-----
>> From: Thierry Besancon [mailto:Thierry(dot)Besancon(at)prism(dot)uvsq(dot)fr]
>> Sent: 20 March 2001 08:34
>> To: Tim Frank
>> Cc: pgsql-admin(at)postgresql(dot)org
>> Subject: Re: [ADMIN] Backing up postgresql databases
>>
>>
>> Dixit Tim Frank <tfrank(at)registrar(dot)uoguelph(dot)ca> (le Tue, 20
>> Mar 2001 00:14:11 GMT) :
>>
>> » Have your shell script do
>> »
>> » export PGUSER=username
>> » export PGPASSWORD=password
>> »
>> » before you run pg_dumpall in the same script. The
>> user/pass would most
>> » likely have to be a superuser to have access to all
>> databases (this is
>> » also not guaranteed depending on your pg_hba.conf). Make
>> the script
>> » read/execute by root but not by anyone else and it will
>> help a tiny bit
>> » with security.
>>
>> Using something like "ps -e" shows the environment variables so it is
>> as unsecure as giving the password on the commande line.
>>
>> Thierry
>>
>> ---------------------------(end of
>> broadcast)---------------------------
>> TIP 6: Have you searched our list archives?
>>
>> http://www.postgresql.org/search.mpl
>>
_________________________________________________________________________
This e-mail and any attachments are confidential and may also be privileged and/or copyright
material of Intec Telecom Systems PLC (or its affiliated companies). If you are not an
intended or authorised recipient of this e-mail or have received it in error, please delete
it immediately and notify the sender by e-mail. In such a case, reading, reproducing,
printing or further dissemination of this e-mail is strictly prohibited and may be unlawful.
Intec Telecom Systems PLC. does not represent or warrant that an attachment hereto is free
from computer viruses or other defects. The opinions expressed in this e-mail and any
attachments may be those of the author and are not necessarily those of Intec Telecom
Systems PLC.
This footnote also confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.
__________________________________________________________________________
From | Date | Subject | |
---|---|---|---|
Next Message | Rachel Coin | 2001-03-20 16:53:38 | Categories and subcategories : more details |
Previous Message | J.H.M. Dassen Ray | 2001-03-20 11:23:39 | Re: Re: cannot create new user in postgres |