agora inbox for pgsql-admin@postgresql.org  
help / color / mirror / Atom feed
From: Rainer Leo <leo@workfile.de>
To: pgsql-admin@lists.postgresql.org
Subject: Re: Remote access on Windows Server
Date: Tue, 2 Jul 2024 14:24:09 +0200
Message-ID: <511001252332521606@workfile.de> (raw)
In-Reply-To: <D3C2CAF4-8504-4E62-9026-D9BD40BFBABC@jakobs.com>
References: <575668296224353060@workfile.de>
	<CAGeimVoupf=JVJgGhxx5YVK75nPgJem4oy=RUk-b3FBzvDf+vg@mail.gmail.com>
	<CAB5fag4jrL=ym9kutzHy+ObvAtah4k7X0QZPc8PiYkCqi7EO7w@mail.gmail.com>
	<D3C2CAF4-8504-4E62-9026-D9BD40BFBABC@jakobs.com>

> What is written to the log when access is attempted?

No entries found in the log





# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


What is written to the log when access is attempted?





Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:


Installation of certificates made from Java will work and make SSL = on



On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:




Hi,




0.0.0/0 trust will make access . This will compromise security.

For rest think of firewall rules








Muhammad Ikram,

Butnine global.









On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:




Hello, we use postgres 13.15 and have to use Windows Datacenter 2022




I cannot figure out how to configure postgres for secure remote access.

It is not possible to use IP whitelisting or VPN, because the user do not
provide anything

beside host/name/port/user/password




# this works but it grants access without password

host    all      all      0.0.0.0/0      trust








# these two are unable to establish connection


host    all      all      0.0.0.0/0      md5

host    all      all      0.0.0.0/0      scram-sha-256







listen_addresses = '*' in postgresql.conf is set







What is the secure way to ensure remote access on Windows Server?




Thanks for any help!




Regards, Leo

view thread (5+ messages)

Message-ID: <511001252332521606@workfile.de>
Permalink:  ../511001252332521606@workfile.de/
Also on:    postgresql.org/message-id/511001252332521606@workfile.de

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: leo@workfile.de, pgsql-admin@lists.postgresql.org
  Subject: Re: Remote access on Windows Server
  In-Reply-To: <511001252332521606@workfile.de>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox