Re: Pg_hba not using local setting

From: Doug McNaught <doug(at)mcnaught(dot)org>
To: James Hall <James(dot)Hall(at)RadioShack(dot)com>
Cc: pgsql-general(at)postgresql(dot)org
Subject: Re: Pg_hba not using local setting
Date: 2003-03-14 16:37:30
Message-ID: m3d6ktgb05.fsf@varsoon.wireboard.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

James Hall <James(dot)Hall(at)RadioShack(dot)com> writes:

> Hello,
>
> Running version 7.1, have the following entry in PG_HBA.CONF:
> ---
> Local all trust
> Host all 123.0.0.0 255.255.255.0
> password
> ---
>
> With that setting, anyone can login to the database [via our web based
> interface]
> WITHOUT a valid password. If I change local from trust to password then web
> based users have to enter their specific password to login to the database.
> But none of the backup scripts run because postgres needs a password.
>
> Is this a bug, or do I have a misunderstanding of the local use?

It sounds like you're running the webserver on the same machine as the
database. If this is true, and if you're not using Java (which
doesn't do local sockets) the client access library is probably using
a local (AF_UNIX) socket to connect, which triggers the "Local" entry
in pg_hba.conf.

If you explicitly tell the webserver to connect using an IP address,
it should come in via a TCP connection and trigger the "Host" line
that you have.

-Doug

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Steve Crawford 2003-03-14 16:39:16 Re: now() AT TIME ZONE interval '-5 hours' returns type interval???
Previous Message Greg Sabino Mullane 2003-03-14 16:37:09 Online docs down again