Search Postgresql Archives

Re: slightly off-topic: Central Auth

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



"Scot Kreienkamp" <SKreien@xxxxxxxxxxxx> writes:
> On 16/10/2009 19:38, Scot Kreienkamp wrote:
>> ...  We are a largely Windows shop with many app and
>> database servers running Linux.  The Linux environment is growing too
>> large not to do centralized authentication of some kind.  

> So I guess what I see taking shape is setting up everything to auth
> against PAM locally, then setting up local PAM to auth to a remote
> source.  

What are you using for central auth in the Windows portions of your
shop?

What I'd suggest is that you standardize on Kerberos auth (that's what
it's called in the Unix world, MS might have another name for it).
You can definitely plug Linux into an Active Directory server for this,
and I believe that you have the option to switch it around in future
if you decide you'd rather have a Linux machine as your central auth
server.

If you decide to go with this approach and use PAM as intermediary,
you'll need the patch I just committed in response to bug #5121 --- it
turns out nobody had ever tried that with Postgres before :-(.  But
I think it's also possible to just use PG's native Kerberos support
with AD, which would explain why nobody had tried it.

			regards, tom lane

-- 
Sent via pgsql-general mailing list (pgsql-general@xxxxxxxxxxxxxx)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-general

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Postgresql Jobs]     [Postgresql Admin]     [Postgresql Performance]     [Linux Clusters]     [PHP Home]     [PHP on Windows]     [Kernel Newbies]     [PHP Classes]     [PHP Books]     [PHP Databases]     [Postgresql & PHP]     [Yosemite]
  Powered by Linux