Re: LDAPS trusted ca support

Marco Cuccato <[email protected]>
Newsgroups gmane.comp.db.postgresql.bugs
Message-ID <CACg0f4Y=x_Dq-HWsks1jLgPiw8qjFbG6GsiqStwq7bhDLpXN5w@mail.gmail.com>
Thanks for the tip!

Il giorno mar 3 dic 2019 alle ore 21:35 Stephen Frost <[email protected]>
ha scritto:

> Greetings,
>
> * Marco Cuccato ([email protected]) wrote:
> > unfortunately I cannot modify the company's LDAP server configuration.
>
> Note that if you're working in an Active Directory environment, you
> should really be considering Kerberos/GSSAPI instead of LDAP for your
> authentication.  Using PostgreSQL's "ldap" auth method means that the
> user's password is sent to, and read by, the PostgreSQL server, which
> isn't really very secure.
>
> You'll definitely also want to be using SSL/TLS between the PostgreSQL
> client system and the PostgreSQL server, but that doesn't help you if
> the PostgreSQL server itself is compromised.
>
> Thanks,
>
> Stephen
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.