From: | wieck(at)debis(dot)com (Jan Wieck) |
---|---|
To: | Lincoln Yeoh <lylyeoh(at)mecomb(dot)com> |
Cc: | Jim Mercer <jim(at)reptiles(dot)org>, Jan Wieck <wieck(at)debis(dot)com>, Peter Eisentraut <peter_e(at)gmx(dot)net>, pgsql-general(at)postgresql(dot)org, pgsql-hackers(at)postgresql(dot)orgg |
Subject: | Re: Re: [HACKERS] pgsql/php3/apache authentication |
Date: | 2000-04-28 01:52:37 |
Message-ID: | m12kzxN-0003lNC@orion.SAPserv.Hamburg.dsh.de |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-general pgsql-hackers |
> >given that, i'm looking at changing things so that i use:
> >
> >local all password
> >host all 127.0.0.1 255.255.255.255 ident sameuser
> >
> >this will force all connections through the unix domain socket to need a
> >password.
> >
> >it will allow unfettered access if the launching process is owned by
> >a valid pg_user.
>
> I always thought ident services should be grouped with fortune cookie
> services and so on :). But, since it's localhost it could work.
Never trust an identd running on a system you don't have a
static ARP entry for - right? Still not secure (on some
systems it's possible to fake the mac address), but good
enough for most purposes.
> >is there a performance penalty associated with forcing the bulk of my
> >processing through the loopback, as opposed to the unix domain socket?
>
> I believe there's a bit more latency but it could be about a millisecond or
> less.
>
> You could always do some benchmarks. e.g. time 1000 queries which return
> lots of data.
One of the reasons for using relational databases is to
reduce the amount of IO needed to get a particular
information. So IPC throughput shouldn't be the a real
problem - except there is some major problem with the DB
layout or the application coding. In that case I'd suggest
if it doesn't fit, don't force it - use a bigger hammer!
Jan
--
#======================================================================#
# It's easier to get forgiveness for being wrong than for being right. #
# Let's break this rule - forgive me. #
#========================================= wieck(at)debis(dot)com (Jan Wieck) #
From | Date | Subject | |
---|---|---|---|
Next Message | Lincoln Yeoh | 2000-04-28 02:14:44 | locking at arbitrary levels. |
Previous Message | Lincoln Yeoh | 2000-04-28 01:12:13 | Re: Re: [HACKERS] pgsql/php3/apache authentication |
From | Date | Subject | |
---|---|---|---|
Next Message | Peter Eisentraut | 2000-04-28 08:05:31 | Re: [HACKERS] pgsql/php3/apache authentication |
Previous Message | Lincoln Yeoh | 2000-04-28 01:12:13 | Re: Re: [HACKERS] pgsql/php3/apache authentication |