Re: BUG #11365: denied apache cgi connect

Поиск
Список
Период
Сортировка
От John R Pierce
Тема Re: BUG #11365: denied apache cgi connect
Дата
Msg-id 540D475C.5010808@hogranch.com
обсуждение исходный текст
Ответ на Re: BUG #11365: denied apache cgi connect  (Jan Wieck <jan@wi3ck.info>)
Ответы Re: BUG #11365: denied apache cgi connect  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-bugs
On 9/7/2014 10:02 PM, Jan Wieck wrote:
>> the PGDG packagers probably should include some level of database
>> selinux policy settings.  maybe a special RPM that sets the apache
>> database policy or something.
>

I probably should have said 'could' instead of 'probably should'.

> "Some special RPM" to do what exactly? Just because someone has
> PostgreSQL and Apache installed on their system doesn't mean they
> wanted httpd to be able to try to connect to their MySQL server on
> another machine in the network. Precisely that is what
> httpd_can_network_connect_db would allow (as a side effect).
>
> So please be more precise in what exactly that special RPM should set
> or enable.

this RPM would be called something like
postgresqlXY-apache-selinuxpolicy, and if installed, it would add the
selinux policy that allows apache to connect to postgres version X.Y as
installed from the same repository.  if uninstalled, it would remove
that policy.


--
john r pierce                                      37N 122W
somewhere on the middle of the left coast

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Jan Wieck
Дата:
Сообщение: Re: BUG #11365: denied apache cgi connect
Следующее
От: Tom Lane
Дата:
Сообщение: Re: BUG #11365: denied apache cgi connect