Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOXHj-00EicL-Gn for pgsql-admin@arkaria.postgresql.org; Tue, 02 Jul 2024 06:46:39 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sOXHh-0065Vb-OL for pgsql-admin@arkaria.postgresql.org; Tue, 02 Jul 2024 06:46:38 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOXHh-0065VM-DZ for pgsql-admin@lists.postgresql.org; Tue, 02 Jul 2024 06:46:37 +0000 Received: from relay.yourmailgateway.de ([188.68.61.103]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sOXHf-0000Vt-Kq for pgsql-admin@lists.postgresql.org; Tue, 02 Jul 2024 06:46:37 +0000 Received: from mors-relay-8403.netcup.net (localhost [127.0.0.1]) by mors-relay-8403.netcup.net (Postfix) with ESMTPS id 4WCtjj5FSHz83Md for ; Tue, 2 Jul 2024 08:46:33 +0200 (CEST) Authentication-Results: mors-relay-8403.netcup.net; dkim=permerror (bad message/signature format) Received: from policy01-mors.netcup.net (unknown [46.38.225.35]) by mors-relay-8403.netcup.net (Postfix) with ESMTPS id 4WCtjj4tVJz83MJ for ; Tue, 2 Jul 2024 08:46:33 +0200 (CEST) X-Virus-Scanned: Debian amavisd-new at policy01-mors.netcup.net X-Spam-Flag: NO X-Spam-Score: -2.9 X-Spam-Level: X-Spam-Status: No, score=-2.9 required=6.31 tests=[ALL_TRUSTED=-1, BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Received: from mx2fb1.netcup.net (unknown [10.243.12.53]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by policy01-mors.netcup.net (Postfix) with ESMTPS id 4WCtjj21LNz8scP for ; Tue, 2 Jul 2024 08:46:33 +0200 (CEST) Received: from [192.168.178.188] (p4fc4be04.dip0.t-ipconnect.de [79.196.190.4]) by mx2fb1.netcup.net (Postfix) with ESMTPSA id A749626F3E for ; Tue, 2 Jul 2024 08:46:28 +0200 (CEST) Authentication-Results: mx2fb1; spf=pass (sender IP is 79.196.190.4) smtp.mailfrom=leo@workfile.de smtp.helo=[192.168.178.188] Received-SPF: pass (mx2fb1: connection is authenticated) From: "Rainer Leo" Subject: Remote access on Windows Server To: "Pgsql-admin" Content-Type: multipart/alternative; charset=UTF-8; boundary="pEh=_pjD8Ug6bY86pmAq6Cg4EEJb68iGXt" MIME-Version: 1.0 Date: Tue, 2 Jul 2024 08:46:24 +0200 Message-Id: <575668296224353060@workfile.de> X-Mailer: EssentialPIM Pro v. 11.8.4 X-PPP-Message-ID: <171990278890.6993.1843441049903633538@mx2fb1.netcup.net> X-Rspamd-Queue-Id: A749626F3E X-Rspamd-Server: rspamd-worker-8404 X-NC-CID: a6bBZEl/+7VqkkS10oGRRtmqVJEyiJFDX1kSI+Gyhw== List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk This is a multi-part message in MIME format --pEh=_pjD8Ug6bY86pmAq6Cg4EEJb68iGXt Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit Content-Disposition: inline Hello, we use postgres 13.15 and have to use Windows Datacenter 2022 I cannot figure out how to configure postgres for secure remote access. It is not possible to use IP whitelisting or VPN, because the user do not provide anything beside host/name/port/user/password # this works but it grants access without password host all all 0.0.0.0/0 trust # these two are unable to establish connection host all all 0.0.0.0/0 md5 host all all 0.0.0.0/0 scram-sha-256 listen_addresses = '*' in postgresql.conf is set What is the secure way to ensure remote access on Windows Server? Thanks for any help! Regards, Leo --pEh=_pjD8Ug6bY86pmAq6Cg4EEJb68iGXt Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: 8bit Content-Disposition: inline
Hello, we use postgres 13.15 and have to use Windows Datacenter 2022

I cannot figure out how to configure postgres for secure remote access.
It is not possible to use IP whitelisting or VPN, because the user do not provide anything
beside host/name/port/user/password

# this works but it grants access without password
host    all      all      0.0.0.0/0      trust


# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


listen_addresses = '*' in postgresql.conf is set


What is the secure way to ensure remote access on Windows Server?

Thanks for any help!

Regards, Leo



--pEh=_pjD8Ug6bY86pmAq6Cg4EEJb68iGXt--