Re: Ldap config for Active Directory

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Sylvain Deveaux <Sylvain(dot)Deveaux(at)niwa(dot)co(dot)nz>
Cc: "pgsql-admin(at)lists(dot)postgresql(dot)org" <pgsql-admin(at)lists(dot)postgresql(dot)org>
Subject: Re: Ldap config for Active Directory
Date: 2022-09-15 22:32:41
Message-ID: YyOoCeCFzP71ziRG@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Greetings,

* Sylvain Deveaux (Sylvain(dot)Deveaux(at)niwa(dot)co(dot)nz) wrote:
> Why do you say that you can't use kerberos w/ apps?
>
> I prefer to not reply to this one otherwise I won't be kind with some people... 😅️

... ok, but let's try to make clear the distinction of "$people won't
let me do this" from "this isn't possible" when posting, as otherwise
people who read the lists may get misled or confused.

> Note that using ldap auth means sending the user's password to the PG
> server in cleartext, which is extremely insecure and means that a
> compromised PG server could be used to steal the credentials of any user
> logging in using this method.
>
> I agree... but for now I can't switch a to full Kerberos setup...

I'd suggest you push back a bit harder on this as it's much, much more
secure to use Kerberos and it's how all the various services in the AD
world operate. Services that pass passwords around in cleartext are
really very insecure.

Thanks,

Stephen

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Ron 2022-09-18 14:58:37 Postgresql version of SQL Server Availability Groups?
Previous Message Sylvain Deveaux 2022-09-15 21:46:47 Re: Ldap config for Active Directory