agora inbox for pgsql-admin@postgresql.org
help / color / mirror / Atom feedRemote access on Windows Server
5+ messages / 4 participants
[nested] [flat]
* Remote access on Windows Server
@ 2024-07-02 06:46 Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
0 siblings, 1 reply; 5+ messages in thread
From: Rainer Leo @ 2024-07-02 06:46 UTC (permalink / raw)
To: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
I cannot figure out how to configure postgres for secure remote access.
It is not possible to use IP whitelisting or VPN, because the user do not
provide anything
beside host/name/port/user/password
# this works but it grants access without password
host all all 0.0.0.0/0 trust
# these two are unable to establish connection
host all all 0.0.0.0/0 md5
host all all 0.0.0.0/0 scram-sha-256
listen_addresses = '*' in postgresql.conf is set
What is the secure way to ensure remote access on Windows Server?
Thanks for any help!
Regards, Leo
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Remote access on Windows Server
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
@ 2024-07-02 07:40 ` Muhammad Ikram <mmikram@gmail.com>
2024-07-02 07:41 ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
0 siblings, 1 reply; 5+ messages in thread
From: Muhammad Ikram @ 2024-07-02 07:40 UTC (permalink / raw)
To: Rainer Leo <leo@workfile.de>; +Cc: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Hi,
0.0.0/0 trust will make access . This will compromise security.
For rest think of firewall rules
Muhammad Ikram,
Butnine global.
On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>
> I cannot figure out how to configure postgres for secure remote access.
> It is not possible to use IP whitelisting or VPN, because the user do not
> provide anything
> beside host/name/port/user/password
>
> # this works but it grants access without password
> host all all 0.0.0.0/0 trust
>
>
> # these two are unable to establish connection
> host all all 0.0.0.0/0 md5
> host all all 0.0.0.0/0 scram-sha-256
>
>
> listen_addresses = '*' in postgresql.conf is set
>
>
> What is the secure way to ensure remote access on Windows Server?
>
> Thanks for any help!
>
> Regards, Leo
>
>
>
>
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Remote access on Windows Server
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
@ 2024-07-02 07:41 ` Wasim Devale <wasimd60@gmail.com>
2024-07-02 08:39 ` Re: Remote access on Windows Server Holger Jakobs <holger@jakobs.com>
0 siblings, 1 reply; 5+ messages in thread
From: Wasim Devale @ 2024-07-02 07:41 UTC (permalink / raw)
To: mmikram@gmail.com; +Cc: leo@workfile.de; pgsql-admin@lists.postgresql.org
Installation of certificates made from Java will work and make SSL = on
On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:
> Hi,
>
> 0.0.0/0 trust will make access . This will compromise security.
> For rest think of firewall rules
>
>
> Muhammad Ikram,
> Butnine global.
>
>
>
> On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
>
>> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>>
>> I cannot figure out how to configure postgres for secure remote access.
>> It is not possible to use IP whitelisting or VPN, because the user do not
>> provide anything
>> beside host/name/port/user/password
>>
>> # this works but it grants access without password
>> host all all 0.0.0.0/0 trust
>>
>>
>> # these two are unable to establish connection
>> host all all 0.0.0.0/0 md5
>> host all all 0.0.0.0/0 scram-sha-256
>>
>>
>> listen_addresses = '*' in postgresql.conf is set
>>
>>
>> What is the secure way to ensure remote access on Windows Server?
>>
>> Thanks for any help!
>>
>> Regards, Leo
>>
>>
>>
>>
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Remote access on Windows Server
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
2024-07-02 07:41 ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
@ 2024-07-02 08:39 ` Holger Jakobs <holger@jakobs.com>
2024-07-02 12:24 ` Re: Remote access on Windows Server Rainer Leo <leo@workfile.de>
0 siblings, 1 reply; 5+ messages in thread
From: Holger Jakobs @ 2024-07-02 08:39 UTC (permalink / raw)
To: pgsql-admin@lists.postgresql.org
# these two are unable to establish connection
host all all 0.0.0.0/0 md5
host all all 0.0.0.0/0 scram-sha-256
What is written to the log when access is attempted?
Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:
>Installation of certificates made from Java will work and make SSL = on
>
>On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:
>
>> Hi,
>>
>> 0.0.0/0 trust will make access . This will compromise security.
>> For rest think of firewall rules
>>
>>
>> Muhammad Ikram,
>> Butnine global.
>>
>>
>>
>> On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
>>
>>> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>>>
>>> I cannot figure out how to configure postgres for secure remote access.
>>> It is not possible to use IP whitelisting or VPN, because the user do not
>>> provide anything
>>> beside host/name/port/user/password
>>>
>>> # this works but it grants access without password
>>> host all all 0.0.0.0/0 trust
>>>
>>>
>>> # these two are unable to establish connection
>>> host all all 0.0.0.0/0 md5
>>> host all all 0.0.0.0/0 scram-sha-256
>>>
>>>
>>> listen_addresses = '*' in postgresql.conf is set
>>>
>>>
>>> What is the secure way to ensure remote access on Windows Server?
>>>
>>> Thanks for any help!
>>>
>>> Regards, Leo
>>>
>>>
>>>
>>>
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Remote access on Windows Server
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
2024-07-02 07:41 ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
2024-07-02 08:39 ` Re: Remote access on Windows Server Holger Jakobs <holger@jakobs.com>
@ 2024-07-02 12:24 ` Rainer Leo <leo@workfile.de>
0 siblings, 0 replies; 5+ messages in thread
From: Rainer Leo @ 2024-07-02 12:24 UTC (permalink / raw)
To: pgsql-admin@lists.postgresql.org
> What is written to the log when access is attempted?
No entries found in the log
# these two are unable to establish connection
host all all 0.0.0.0/0 md5
host all all 0.0.0.0/0 scram-sha-256
What is written to the log when access is attempted?
Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:
Installation of certificates made from Java will work and make SSL = on
On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:
Hi,
0.0.0/0 trust will make access . This will compromise security.
For rest think of firewall rules
Muhammad Ikram,
Butnine global.
On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
I cannot figure out how to configure postgres for secure remote access.
It is not possible to use IP whitelisting or VPN, because the user do not
provide anything
beside host/name/port/user/password
# this works but it grants access without password
host all all 0.0.0.0/0 trust
# these two are unable to establish connection
host all all 0.0.0.0/0 md5
host all all 0.0.0.0/0 scram-sha-256
listen_addresses = '*' in postgresql.conf is set
What is the secure way to ensure remote access on Windows Server?
Thanks for any help!
Regards, Leo
^ permalink raw reply [nested|flat] 5+ messages in thread
end of thread, other threads:[~2024-07-02 12:24 UTC | newest]
Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Muhammad Ikram <mmikram@gmail.com>
2024-07-02 07:41 ` Wasim Devale <wasimd60@gmail.com>
2024-07-02 08:39 ` Holger Jakobs <holger@jakobs.com>
2024-07-02 12:24 ` Rainer Leo <leo@workfile.de>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox