Re: LDAPS trusted ca support

Stephen Frost <[email protected]>
Newsgroups gmane.comp.db.postgresql.bugs
Message-ID <[email protected]>
Greetings,

* Marco Cuccato ([email protected]) wrote:
> unfortunately I cannot modify the company's LDAP server configuration.

Note that if you're working in an Active Directory environment, you
should really be considering Kerberos/GSSAPI instead of LDAP for your
authentication.  Using PostgreSQL's "ldap" auth method means that the
user's password is sent to, and read by, the PostgreSQL server, which
isn't really very secure.

You'll definitely also want to be using SSL/TLS between the PostgreSQL
client system and the PostgreSQL server, but that doesn't help you if
the PostgreSQL server itself is compromised.

Thanks,

Stephen
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJd5scOAAoJEO1sijiDR2RVZuwP/1EK3A/WynHzhm745Fpj1rHU
yL2TUqwXH278bR+OprQ3RZOk1yc324cV8F9hhpl6MnaJllt9fhL/xt4VEEWCDkqR
hAILdJdNzxyuacaMjNlw0Z7i+6CMO7+Uhma6Wwv0ZMF05+TDiR9/6hmANVcTqsyL
OTcvtgahf9vrruqPW6X6lQNgmaqmQtyU8OJ3pVULsTZ75pPOf6Wv8/hZGEa5+Kxp
uOpuJpW67BhrHyIX8E1MORa1HYVnoKHs2scQUippLHHzEy6HwYwdgPwIYAOB2C1h
w//YXxRULkkb0Xqr2Nu4owEG5PO4aIMbQOV2OdcksyiLy9nQHqiBpNSzQ3xIrLDB
Dj9N3Z+XeoJcgPMLHLpW1nTeCDimwq9gOY/C9JpejdInWTnPKnBmNowf37fF0NeZ
bniiip48RINaKhERE6KwmgKqrBpkYuJjkeh9m/W3f8aD5QDZdO9xxDt4tFrqoAfm
F2p6S6O6McyrB/ZpzoQLwBq1bVC97JldpgOQNzc7ggK6spQEFPSPTJ79OgNZyeTq
A7eqN+YoqBvtH1i0K7WK9H34rIlJyjhdBlr5hUdC6KfvP9SukthDCjTEnzCH3FDZ
tgoM9f4DLVwFt4qBLBFhCYuOxKEAlNyCXXeLDRFVLVcgOGOp3TKOJf6bCOu1vXD0
MwD2GTb/EpwyYnRcctvM
=ldTQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.