[Bug 753027] Review Request: pam-pgsql - PAM module to authenticate using a PostgreSQL database

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=753027



--- Comment #9 from Mathieu Bridon <bochecha@xxxxxxxxxxxxxxxxx> ---
(In reply to Florian Weimer from comment #8)
> I don't think libpq (the PostgreSQL client library) is designed to be used
> in a SUID process, so this PAM module is likely not entirely safe to use as
> the system default.

Do you mean you wouldn't recommend to introduce this package in Fedora at all?

Or do you mean that if this package is introduced into Fedora, then it should
not be used on a default Fedora install?

I certainly don't intend to do the latter, and if you have strong concerns over
the security of this package, maybe even the former is not a great idea? :-/

(I still didn't have time to resolve the selinux issues mentioned in comment 3,
which might be an additional concern)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
_______________________________________________
package-review mailing list
package-review@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/package-review





[Index of Archives]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]