agora inbox for pgsql-admin@postgresql.org  
help / color / mirror / Atom feed
Remote access on Windows Server
5+ messages / 4 participants
[nested] [flat]

* Remote access on Windows Server
@ 2024-07-02 06:46 Rainer Leo <leo@workfile.de>
  2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
  0 siblings, 1 reply; 5+ messages in thread

From: Rainer Leo @ 2024-07-02 06:46 UTC (permalink / raw)
  To: Pgsql-admin <pgsql-admin@lists.postgresql.org>

Hello, we use postgres 13.15 and have to use Windows Datacenter 2022




I cannot figure out how to configure postgres for secure remote access.

It is not possible to use IP whitelisting or VPN, because the user do not
provide anything

beside host/name/port/user/password




# this works but it grants access without password

host    all      all      0.0.0.0/0      trust








# these two are unable to establish connection


host    all      all      0.0.0.0/0      md5

host    all      all      0.0.0.0/0      scram-sha-256







listen_addresses = '*' in postgresql.conf is set







What is the secure way to ensure remote access on Windows Server?




Thanks for any help!




Regards, Leo

^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Remote access on Windows Server
  2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
@ 2024-07-02 07:40 ` Muhammad Ikram <mmikram@gmail.com>
  2024-07-02 07:41   ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
  0 siblings, 1 reply; 5+ messages in thread

From: Muhammad Ikram @ 2024-07-02 07:40 UTC (permalink / raw)
  To: Rainer Leo <leo@workfile.de>; +Cc: Pgsql-admin <pgsql-admin@lists.postgresql.org>

Hi,

0.0.0/0 trust will make access . This will compromise security.
For rest think of firewall rules


Muhammad Ikram,
Butnine global.



On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:

> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>
> I cannot figure out how to configure postgres for secure remote access.
> It is not possible to use IP whitelisting or VPN, because the user do not
> provide anything
> beside host/name/port/user/password
>
> # this works but it grants access without password
> host    all      all      0.0.0.0/0      trust
>
>
> # these two are unable to establish connection
> host    all      all      0.0.0.0/0      md5
> host    all      all      0.0.0.0/0      scram-sha-256
>
>
> listen_addresses = '*' in postgresql.conf is set
>
>
> What is the secure way to ensure remote access on Windows Server?
>
> Thanks for any help!
>
> Regards, Leo
>
>
>
>

^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Remote access on Windows Server
  2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
  2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
@ 2024-07-02 07:41   ` Wasim Devale <wasimd60@gmail.com>
  2024-07-02 08:39     ` Re: Remote access on Windows Server Holger Jakobs <holger@jakobs.com>
  0 siblings, 1 reply; 5+ messages in thread

From: Wasim Devale @ 2024-07-02 07:41 UTC (permalink / raw)
  To: mmikram@gmail.com; +Cc: leo@workfile.de; pgsql-admin@lists.postgresql.org

Installation of certificates made from Java will work and make SSL = on

On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:

> Hi,
>
> 0.0.0/0 trust will make access . This will compromise security.
> For rest think of firewall rules
>
>
> Muhammad Ikram,
> Butnine global.
>
>
>
> On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
>
>> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>>
>> I cannot figure out how to configure postgres for secure remote access.
>> It is not possible to use IP whitelisting or VPN, because the user do not
>> provide anything
>> beside host/name/port/user/password
>>
>> # this works but it grants access without password
>> host    all      all      0.0.0.0/0      trust
>>
>>
>> # these two are unable to establish connection
>> host    all      all      0.0.0.0/0      md5
>> host    all      all      0.0.0.0/0      scram-sha-256
>>
>>
>> listen_addresses = '*' in postgresql.conf is set
>>
>>
>> What is the secure way to ensure remote access on Windows Server?
>>
>> Thanks for any help!
>>
>> Regards, Leo
>>
>>
>>
>>

^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Remote access on Windows Server
  2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
  2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
  2024-07-02 07:41   ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
@ 2024-07-02 08:39     ` Holger Jakobs <holger@jakobs.com>
  2024-07-02 12:24       ` Re: Remote access on Windows Server Rainer Leo <leo@workfile.de>
  0 siblings, 1 reply; 5+ messages in thread

From: Holger Jakobs @ 2024-07-02 08:39 UTC (permalink / raw)
  To: pgsql-admin@lists.postgresql.org

# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


What is written to the log when access is attempted? 


Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:
>Installation of certificates made from Java will work and make SSL = on
>
>On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:
>
>> Hi,
>>
>> 0.0.0/0 trust will make access . This will compromise security.
>> For rest think of firewall rules
>>
>>
>> Muhammad Ikram,
>> Butnine global.
>>
>>
>>
>> On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:
>>
>>> Hello, we use postgres 13.15 and have to use Windows Datacenter 2022
>>>
>>> I cannot figure out how to configure postgres for secure remote access.
>>> It is not possible to use IP whitelisting or VPN, because the user do not
>>> provide anything
>>> beside host/name/port/user/password
>>>
>>> # this works but it grants access without password
>>> host    all      all      0.0.0.0/0      trust
>>>
>>>
>>> # these two are unable to establish connection
>>> host    all      all      0.0.0.0/0      md5
>>> host    all      all      0.0.0.0/0      scram-sha-256
>>>
>>>
>>> listen_addresses = '*' in postgresql.conf is set
>>>
>>>
>>> What is the secure way to ensure remote access on Windows Server?
>>>
>>> Thanks for any help!
>>>
>>> Regards, Leo
>>>
>>>
>>>
>>>

^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Remote access on Windows Server
  2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
  2024-07-02 07:40 ` Re: Remote access on Windows Server Muhammad Ikram <mmikram@gmail.com>
  2024-07-02 07:41   ` Re: Remote access on Windows Server Wasim Devale <wasimd60@gmail.com>
  2024-07-02 08:39     ` Re: Remote access on Windows Server Holger Jakobs <holger@jakobs.com>
@ 2024-07-02 12:24       ` Rainer Leo <leo@workfile.de>
  0 siblings, 0 replies; 5+ messages in thread

From: Rainer Leo @ 2024-07-02 12:24 UTC (permalink / raw)
  To: pgsql-admin@lists.postgresql.org

> What is written to the log when access is attempted?

No entries found in the log





# these two are unable to establish connection
host    all      all      0.0.0.0/0      md5
host    all      all      0.0.0.0/0      scram-sha-256


What is written to the log when access is attempted?





Am 2. Juli 2024 09:41:44 MESZ schrieb Wasim Devale <wasimd60@gmail.com>:


Installation of certificates made from Java will work and make SSL = on



On Tue, 2 Jul, 2024, 1:10 pm Muhammad Ikram, <mmikram@gmail.com> wrote:




Hi,




0.0.0/0 trust will make access . This will compromise security.

For rest think of firewall rules








Muhammad Ikram,

Butnine global.









On Tue, 2 Jul 2024 at 11:46, Rainer Leo <leo@workfile.de> wrote:




Hello, we use postgres 13.15 and have to use Windows Datacenter 2022




I cannot figure out how to configure postgres for secure remote access.

It is not possible to use IP whitelisting or VPN, because the user do not
provide anything

beside host/name/port/user/password




# this works but it grants access without password

host    all      all      0.0.0.0/0      trust








# these two are unable to establish connection


host    all      all      0.0.0.0/0      md5

host    all      all      0.0.0.0/0      scram-sha-256







listen_addresses = '*' in postgresql.conf is set







What is the secure way to ensure remote access on Windows Server?




Thanks for any help!




Regards, Leo

^ permalink  raw  reply  [nested|flat] 5+ messages in thread


end of thread, other threads:[~2024-07-02 12:24 UTC | newest]

Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-07-02 06:46 Remote access on Windows Server Rainer Leo <leo@workfile.de>
2024-07-02 07:40 ` Muhammad Ikram <mmikram@gmail.com>
2024-07-02 07:41   ` Wasim Devale <wasimd60@gmail.com>
2024-07-02 08:39     ` Holger Jakobs <holger@jakobs.com>
2024-07-02 12:24       ` Rainer Leo <leo@workfile.de>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox