From: | Pär Mattsson <par(dot)x(dot)mattsson(at)gmail(dot)com> |
---|---|
To: | Holger Jakobs <holger(at)jakobs(dot)com>, "pgsql-admin(at)lists(dot)postgresql(dot)org" <pgsql-admin(at)lists(dot)postgresql(dot)org> |
Subject: | Re: Use AD-account as login into Postgres. |
Date: | 2024-02-09 19:31:51 |
Message-ID: | GV1P189MB2132634A059A3C37E102BF83A24B2@GV1P189MB2132.EURP189.PROD.OUTLOOK.COM |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-admin |
Yes this is a complete windows installation of Postgres and they will use ad-login account into the database
Mvh Pär
________________________________
Från: Holger Jakobs <holger(at)jakobs(dot)com>
Skickat: fredag, februari 9, 2024 20:05
Till: pgsql-admin(at)lists(dot)postgresql(dot)org <pgsql-admin(at)lists(dot)postgresql(dot)org>
Ämne: Re: Use AD-account as login into Postgres.
Am 09.02.24 um 19:31 schrieb Pär Mattsson:
Hi!
Is it only to config in hba.conf the connection info, to use AD-accounts to login in postgres.
This is a windows/postres intallation 🤦♂️✌️
Mvh Pär
+46706069645
Hi,
Short answer: No!
SSPI using AD accounts for authentication works only in a complete Windows environment. The client and the server machine have to be member of the same AD environment, which isn't possible for non-Windows machines. Otherwise, there is no trust between the machines.
An automatic creation of PostgreSQL roles from AD accounts has to be done outside PostgreSQL, i. e. by a script running regularly.
A couple of years ago, I wrote such a script for a customer.
Regards,
Holger
--
Holger Jakobs, Bergisch Gladbach, Tel. +49-178-9759012
From | Date | Subject | |
---|---|---|---|
Next Message | Holger Jakobs | 2024-02-09 19:34:42 | Re: Use AD-account as login into Postgres. |
Previous Message | Holger Jakobs | 2024-02-09 19:05:23 | Re: Use AD-account as login into Postgres. |