Re: Log of CREATE USER statement

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: Log of CREATE USER statement
Дата
Msg-id 200512091937.39147.peter_e@gmx.net
обсуждение исходный текст
Ответ на Re: Log of CREATE USER statement  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Tom Lane wrote:
> To put that more clearly: if the point is to keep the user's
> cleartext password out of the hands of the DBA, then the user has
> already blown it by sending the password in cleartext in the first
> place.  An untrustworthy DBA could trivially insert code into CREATE
> USER to log the original password in a place of his choosing.

With SELinux or similar systems, it might be the case that the DBA could 
not change or insert any code but could configure and read the server 
logs.  But this is admittedly a rare case currently.

-- 
Peter Eisentraut
http://developer.postgresql.org/~petere/


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Martijn van Oosterhout
Дата:
Сообщение: Re: Upcoming PG re-releases
Следующее
От: Peter Eisentraut
Дата:
Сообщение: Re: Log of CREATE USER statement