From: | Denis Pugnere <Denis(dot)Pugnere(at)igh(dot)cnrs(dot)fr> |
---|---|
To: | pgsql-admin(at)postgresql(dot)org |
Subject: | users and passwords problem |
Date: | 2000-07-13 13:43:54 |
Message-ID: | Pine.LNX.4.10.10007131519420.16473-100000@pegase.igh.cnrs.fr |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-admin |
PG 7.0.2, RH Linux 6.2
I'm trying to secure access to pgsql databases.
the politic I use is to only allow access databases with passwords.
for this, I use in pg_hba.conf :
local all password
host all 127.0.0.1 255.255.255.255 password
I don't understand why with this configuration I can access to all
databases even if I'm not the owner, for example : If the database test is
owned by user1 and this user has all grants on all tables in this
database, every user created with "CREATE USER ..." (with or without
password) in the local system can run a command like :
user2% psql test -U user1
Welcome to psql, the PostgreSQL interactive terminal.
Type: \copyright for distribution terms
\h for help with SQL commands
\? for help on internal slash commands
\g or terminate with semicolon to execute query
\q to quit
test=>
Why this access is allowed ?
How to secure accesses to databases ?
I don't see where is the problem.
Thanks for your suggestions.
Denis Pugnère
From | Date | Subject | |
---|---|---|---|
Next Message | Anthony E. Greene | 2000-07-13 14:06:50 | Re: users and passwords problem |
Previous Message | Jeremy Buchmann | 2000-07-13 00:16:54 | Safe/unsafe optimization flags |