Re: Fwd: Log file

From: Igor Korot <ikorot01(at)gmail(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: pgsql-general <pgsql-general(at)postgresql(dot)org>
Subject: Re: Fwd: Log file
Date: 2018-10-31 04:32:33
Message-ID: CA+FnnTy3w426agu3pxk2Yx_Og_682UaqZg2bcyc8mZ0W1sfqNw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-odbc

Hi, Tom,

On Mon, Oct 29, 2018 at 5:08 PM Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
>
> Igor Korot <ikorot01(at)gmail(dot)com> writes:
> > On Mon, Oct 29, 2018 at 1:56 PM Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
> >> You can set up the log files as readable by the OS group of the server
> >> (see log_file_mode), and then grant membership in that group to whichever
> >> OS accounts you trust. You may also need to move the log directory
> >> out from under $PGDATA to make that work, since PG doesn't like
> >> world-readable data directories.
>
> > I'm trying to make the log file of PG readable of the user who logs in
> > to the current
> > OS session. I don't need a write permission, just read.
> > Because my program will not be started from the "postgres" account.
>
> Well, any such setup is a serious security hole in itself, because
> there is likely to be sensitive data in the postmaster log, eg
> passwords. (Remember that the log file is global to the whole cluster,
> it will not contain just data relevant to the current session.)
> You should only grant access to people who you trust at more or less
> the level of trust you'd put in the installation DBA.
>
> It may be that these concerns are all irrelevant to you because it's
> a single-user installation anyway, but they're not irrelevant to
> people running multi-user installations. So that's why you can't
> get Postgres to do it. In a single-user installation, maybe you
> should just launch the postmaster as that user.
>
> regards, tom lane

OK, I understand.

Thank you.

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Torsten Förtsch 2018-10-31 05:38:13 Is there a way to speed up WAL replay?
Previous Message Amit Langote 2018-10-31 01:50:19 Re: Should pg 11 use a lot more memory building an spgist index?

Browse pgsql-odbc by date

  From Date Subject
Next Message Laurenz Albe 2018-10-31 07:00:21 Re: Fwd: Log file
Previous Message Igor Korot 2018-10-30 16:20:50 Re: Fwd: Log file