Re: [HACKERS] Solaris ident authentication using unix domain sockets

Andrew Dunstan <[email protected]>
Newsgroups gmane.comp.db.postgresql.devel.patches,gmane.comp.db.postgresql.devel.general
Message-ID <[email protected]>

Josh Berkus wrote:
> Tom,
>
>   
>> Indeed.  If the Solaris folk feel that getupeercred() is insecure,
>> they had better explain why their kernel is that broken.  This is
>> entirely unrelated to the known shortcomings of the "ident" IP
>> protocol.
>>     
>
> The Solaris security & kernel folks do, actually.  However, there's no 
> question that TRUST is inherently insecure, and that's what people are going 
> to use if they can't get IDENT to work.
>
>   


I think I'd pose a slightly different question from Tom. Do the Solaris 
devs think that their getupeercred() is more insecure than the more or 
less equivalent calls that we are doing on Linux and *BSD for example? I 
suspect they probably don't ;-)

cheers

andrew



-- 
Sent via pgsql-patches mailing list ([email protected])
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-patches
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.