Re: Update actions (with user name) inside PostgreSQL DB - any version on postgreSQL

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Khangelani Gama <kgama@xxxxxxxxxxxx> wrote:
 
> the issue we have is that we have many Linux users having root
> access into the system.
 
Which gives them rights to impersonate any other user on the system
and to erase any audit trail written on that system.
 
> Auditors wants PostgreSQL to tell who updated what inside the
> database
 
You might be able to create something which looks plausible without
solving the first problem, but it wouldn't be at all trustworthy. 
Consider limiting access to root on your database servers and, in
general, pay attention to the concept of "separation of duties"[1].
 
-Kevin
 
[1] http://en.wikipedia.org/wiki/Separation_of_duties

-- 
Sent via pgsql-admin mailing list (pgsql-admin@xxxxxxxxxxxxxx)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-admin


[Index of Archives]     [KVM ARM]     [KVM ia64]     [KVM ppc]     [Virtualization Tools]     [Spice Development]     [Libvirt]     [Libvirt Users]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite Questions]     [Linux Kernel]     [Linux SCSI]     [XFree86]

  Powered by Linux