Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOcYY-000HjX-FJ for pgsql-admin@arkaria.postgresql.org; Tue, 02 Jul 2024 12:24:22 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sOcYW-001WSa-By for pgsql-admin@arkaria.postgresql.org; Tue, 02 Jul 2024 12:24:21 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOcYV-001WSS-TE for pgsql-admin@lists.postgresql.org; Tue, 02 Jul 2024 12:24:20 +0000 Received: from relay.yourmailgateway.de ([188.68.63.162]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOcYS-00027M-TU for pgsql-admin@lists.postgresql.org; Tue, 02 Jul 2024 12:24:19 +0000 Received: from mors-relay-8201.netcup.net (localhost [127.0.0.1]) by mors-relay-8201.netcup.net (Postfix) with ESMTPS id 4WD2CK5jXmz3xrL for ; Tue, 2 Jul 2024 14:24:13 +0200 (CEST) Authentication-Results: mors-relay-8201.netcup.net; dkim=permerror (bad message/signature format) Received: from policy02-mors.netcup.net (unknown [46.38.225.35]) by mors-relay-8201.netcup.net (Postfix) with ESMTPS id 4WD2CK50pXz3xrF for ; Tue, 2 Jul 2024 14:24:13 +0200 (CEST) Received: from mx2fb1.netcup.net (unknown [10.243.12.53]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by policy02-mors.netcup.net (Postfix) with ESMTPS id 4WD2CK3Hg1z8scM for ; Tue, 2 Jul 2024 14:24:13 +0200 (CEST) Received: from [192.168.178.188] (p4fc4be04.dip0.t-ipconnect.de [79.196.190.4]) by mx2fb1.netcup.net (Postfix) with ESMTPSA id 805E62285D for ; Tue, 2 Jul 2024 14:24:08 +0200 (CEST) Authentication-Results: mx2fb1; spf=pass (sender IP is 79.196.190.4) smtp.mailfrom=leo@workfile.de smtp.helo=[192.168.178.188] Received-SPF: pass (mx2fb1: connection is authenticated) From: "Rainer Leo" Subject: Re: Remote access on Windows Server To: pgsql-admin@lists.postgresql.org Content-Type: multipart/alternative; charset=UTF-8; boundary="sZzc=_fTo9ehnNwUVwcbw8EwwEPwDA9eu7" MIME-Version: 1.0 References: <575668296224353060@workfile.de> Date: Tue, 2 Jul 2024 14:24:09 +0200 Message-Id: <511001252332521606@workfile.de> In-Reply-To: X-Mailer: EssentialPIM Pro v. 11.8.4 X-Rspamd-Queue-Id: 805E62285D X-Rspamd-Server: rspamd-worker-8404 X-NC-CID: Li6lkgPL+cns2t3FZmLTIKDNOhiIh9krGGicJAXlTQ== List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk This is a multi-part message in MIME format --sZzc=_fTo9ehnNwUVwcbw8EwwEPwDA9eu7 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit Content-Disposition: inline > What is written to the log when access is attempted? No entries found in the log # these two are unable to establish connection host all all 0.0.0.0/0 md5 host all all 0.0.0.0/0 scram-sha-256 What is written to the log when access is attempted? Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale : Installation of certificates made from Java will work and make SSL = on On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, wrote: Hi, 0.0.0/0 trust will make access . This will compromise security. For rest think of firewall rules Muhammad Ikram, Butnine global. On Tue, 2 Jul 2024 at 11:46, Rainer Leo wrote: Hello, we use postgres 13.15 and have to use Windows Datacenter 2022 I cannot figure out how to configure postgres for secure remote access. It is not possible to use IP whitelisting or VPN, because the user do not provide anything beside host/name/port/user/password # this works but it grants access without password host all all 0.0.0.0/0 trust # these two are unable to establish connection host all all 0.0.0.0/0 md5 host all all 0.0.0.0/0 scram-sha-256 listen_addresses = '*' in postgresql.conf is set What is the secure way to ensure remote access on Windows Server? Thanks for any help! Regards, Leo --sZzc=_fTo9ehnNwUVwcbw8EwwEPwDA9eu7 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: 8bit Content-Disposition: inline
​
> What is written to the log when access is attempted?
No entries found in the log

# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


What is written to the log when access is attempted?


Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:

Installation of certificates made from Java will work and make SSL = on


On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:
Hi,

0.0.0/0 trust will make access . This will compromise security.
For rest think of firewall rules


Muhammad Ikram,
Butnine global.



On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
Hello, we use postgres 13.15 and have to use Windows Datacenter 2022

I cannot figure out how to configure postgres for secure remote access.
It is not possible to use IP whitelisting or VPN, because the user do not provide anything
beside host/name/port/user/password

# this works but it grants access without password
host    all      all      0.0.0.0/0      trust


# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


listen_addresses = '*' in postgresql.conf is set


What is the secure way to ensure remote access on Windows Server?

Thanks for any help!

Regards, Leo




--sZzc=_fTo9ehnNwUVwcbw8EwwEPwDA9eu7--