Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UZlnt-0007qd-9E for pgsql-admin@arkaria.postgresql.org; Tue, 07 May 2013 17:35:53 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.72) (envelope-from ) id 1UZlns-00052O-P4 for pgsql-admin@arkaria.postgresql.org; Tue, 07 May 2013 17:35:52 +0000 Received: from makus.postgresql.org ([2001:4800:7903:4::125]) by malur.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UZlM9-0000bP-5a for pgsql-admin@postgresql.org; Tue, 07 May 2013 17:07:13 +0000 Received: from nm13-vm5.bullet.mail.gq1.yahoo.com ([98.136.218.236]) by makus.postgresql.org with smtp (Exim 4.72) (envelope-from ) id 1UZlM5-0008AD-R2 for pgsql-admin@postgresql.org; Tue, 07 May 2013 17:07:12 +0000 Received: from [98.137.12.191] by nm13.bullet.mail.gq1.yahoo.com with NNFMP; 07 May 2013 17:07:09 -0000 Received: from [98.137.12.239] by tm12.bullet.mail.gq1.yahoo.com with NNFMP; 07 May 2013 17:07:08 -0000 Received: from [127.0.0.1] by omp1047.mail.gq1.yahoo.com with NNFMP; 07 May 2013 17:07:08 -0000 X-Yahoo-Newman-Property: ymail-3 X-Yahoo-Newman-Id: 947636.45072.bm@omp1047.mail.gq1.yahoo.com Received: (qmail 1833 invoked by uid 60001); 7 May 2013 17:07:08 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1367946428; bh=irSQQBCh7L9OLwJ7R5eT+icMRgpsDdxKRwN+u2nZW+s=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type; b=gfW5SaslLCpB4IHiGBbf/IIdVb7MXdZvyuJPokecpm0sPORg5dMqxjUZ6yjDvPtAN6mqlA5BDijTCdh0O+PhvRAIBYHUALG5ZfIDYlNRDwAig2bbS05/LFeqsWECyYMD6kDNdbsONadMG+heQe4io3SM54EG5rNdPTWBto2gys4= DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type; b=KXoDIs80NaxMJJrvNm5nhAAic3JiKKNWMtjGBjFknIUVR9sQLsKdXq0eQPe4Ue1/N/cs+OgdU2himvIc7mGyaxzwjOsA0mxzrTYFtw1XBIWZPyT58bf7q8rUzjx0p0vcXjXtSrGSIfsDEouNruHrQPJ9G+zv48IT4cK55FNsKgU=; X-YMail-OSG: XzPlcrUVM1kgCTQN1KJfICzErCGMfI1.WLAluD13tAY4mDp LGu26MDnyeQujYWdUYyl7p7C9qupVOfoyscc4o1C66o0QMTm6xLvFfCBaAMy 46fbEDsAiosiMPtX5_JzP7PKq1CeOC_ip_iMld7DmL2VdXSDZG2v0gaq8sN8 rmK55wRjmuN_JMcexclrBEIJXCeajnpP1ocVHrfDfC4AbdQ68RqL6nuYKo2k 2Twa6ItVYucSQWQIZYAWgcBcnUf16pyqUqn0Uzj9qnozW5s7TloNsrxzSP5k 1_RRDK20jCu4.K.fbwOZAlUbEco_YNZeE.adYyYjuCMNecFkx2OQjusecYh7 Lh7JNSkhGdR1iyqLQL2ftHSsfY21WHQMA0uxB_kNooZKUTU04M1aMxVXk8V2 kL9H9GJqbTmdiPk4WvPJy0ugp8g1qUkXZn9lkeZeP_ewkhupYbSfEb34tGEz ZKhXExmwShwZxEJsqQLWu_wU3RQOztqOynOOsGkeCg1kbs0s.VZzLOeO3QQp .8RAcIcFBMXVPT9kWKjuVq_AS_7InxVuxHj7JY0128pFAVJPav.otvvByvDq BgJCN9wbjB81M17x.672BTouKUyu2P7uj2zreBvy566Tf66j0CJKdZLGOnDH .cfH6WwT779Ot99FWZC3sL5fCE0DACpn2chy.cwk0PZar5Wue_bmuQJNx5MO EeSw5j.XkIDCyzKrrzmBQ8gYgwUgKfOiMd5lSzx1ADkZ3F7aBxuX0kJdczEh rjhBjGVNAKTppedxvX9sXMbHvJ9clZ2LruzSwR2WLxkye1Rij7MGkuhcs5Gy MJtrYMkuQM2.utpTuWfQEzhI6zlLL7JNqB0rkWip824KjYxRlLcT7IyN2cUG 2IRM0idfSnwWQraqxnjqL9DtCOBtLRK05fuNgSruLp2Xly00cqspSUg-- Received: from [12.88.149.126] by web163503.mail.gq1.yahoo.com via HTTP; Tue, 07 May 2013 10:07:08 PDT X-Rocket-MIMEInfo: 002.001, SGVyZSBpcyBteSB1bmRlcnN0YWRpbmcgb2YgeW91ciByZXF1aXJlbWVudDoKwqAKbWFjaGluZS1BIGF0IGN1c3RvbWVyIHNpdGUgd291bGQgcmVwbGljYXRlIHRvIHN0YWdpbmcgbWFjaGluZS1CIHdoaWNoIHdpbGwgdGhlbiByZXBsaWNhdGUgdG8gdGFyZ2V0IG1hY2hpbmUtQyBpbiBjbG91ZCAtIGFuZCB5b3Ugd291bGQgd2FudCB0byBlbmNyeXB0IGRhdGEgaW4gbW90aW9uIGZyb20gQSB0byBCIHRvIEMuCsKgCkkgY291bGQgdGhpbmsgb2YgMiBwb3NzaWJsZSBzb2x1dGlvbnM6CsKgCjEuIFVzZSBTdHVubmUBMAEBAQE- X-Mailer: YahooMailWebService/0.8.141.536 References: <515AEB4E.9010305@europecamions-interactive.com> <1365617192.69337.YahooMailNeo@web163506.mail.gq1.yahoo.com> <20130410181656.GB32580@aart.rice.edu> <1367943441337-5754606.post@n5.nabble.com> Message-ID: <1367946428.1661.YahooMailNeo@web163503.mail.gq1.yahoo.com> Date: Tue, 7 May 2013 10:07:08 -0700 (PDT) From: Bhanu Murthy Reply-To: Bhanu Murthy Subject: Re: [SQL] Encrypting PGBouncer to Postgres DB connections To: handsfree , "pgsql-admin@postgresql.org" In-Reply-To: <1367943441337-5754606.post@n5.nabble.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="48240482-1519852437-1367946428=:1661" X-Pg-Spam-Score: -2.2 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-admin Precedence: bulk Sender: pgsql-admin-owner@postgresql.org --48240482-1519852437-1367946428=:1661 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Here is my understading of your requirement:=0A=A0=0Amachine-A at customer = site would replicate to staging machine-B which will then replicate to targ= et machine-C in cloud - and you would want to encrypt data in motion from A= to B to C.=0A=A0=0AI could think of 2 possible solutions:=0A=A0=0A1. Use S= tunnel from machine-A to machine-B, and again from machine-B to machine-C. = =0A=A0=0A=A0=0A2. Use streaming replication config features to secure traff= ic (encrypted=A0data over=A0TCP)=0A=A0=0AMaster configuration on machine-A:= =0A=3D>Update=A0replication line in pg_hba.conf=A0to "hostssl"=0A=0ASlave c= onfiguration on machine-B:=0A=3D> primary_conninfo=3D'host=3Dmachine-A port= =3D5432 sslmode=3Drequire' =0Aor=0A=3D> primary_conninfo=3D'host=3Dmachine-= A port=3D5432 sslmode=3Dverify-ca'=0A=A0=0AYou could then use cascading rep= lication (available from postgres 9.2) from machine-B to machine-C.=0A=A0 = =0A=0A________________________________=0A From: handsfree =0ATo: pgsql-admin@postgresql.org =0ASent: Tuesday, May 7, 2013 9= :17 AM=0ASubject: Re: [ADMIN] [SQL] Encrypting PGBouncer to Postgres DB con= nections=0A =0A=0AWe're looking to use streaming replication to a target v= ia a secondary host=0Ausing stunnel.=A0 I'd love to hear how you were able = to achieve this,=0Aktm@rice.edu.=0A=0AEffectively we're looking to have the= database on our customer's site (let's=0Acall that MachineA) replicate to = our backend postgres target in the cloud=0A(let's call that MachineC).=A0 H= owever, MachineA has no direct communication=0Awith MachineC, in fact, it s= hould never be allowed to communicate with it. =0AWe have another server th= at provides various services to the client MachineA=0Athat is based in our = home datacenter (let's call that MachineB) which we=0Awould like to use as = a 'staging' machine for the replication to the database=0Areplication targe= t.=A0 Is this possible to achieve using stunnel (and=0Apgbouncer?) alone?= =A0 =0A=0AAt no point can this traffic go 'in the clear', for obvious reaso= ns ;)=0A=0AAny pointers or assistance help gratefully received!=A0 Thanks= =0A=0A=0A=0A--=0AView this message in context: http://postgresql.1045698.n5= .nabble.com/Hot-standby-with-streaming-replication-under-PgSQL-9-1-x-failov= er-when-master-crashes-tp5750442p5754606.html=0ASent from the PostgreSQL - = admin mailing list archive at Nabble.com.=0A=0A=0A-- =0ASent via pgsql-admi= n mailing list (pgsql-admin@postgresql.org)=0ATo make changes to your subsc= ription:=0Ahttp://www.postgresql.org/mailpref/pgsql-admin --48240482-1519852437-1367946428=:1661 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable
Here is my understa= ding of your requirement:
 
machine-A at customer site would replicate to staging machine-B which w= ill then replicate to target machine-C in cloud - and you would want to enc= rypt data in motion from A to B to C.
 <= /div>
I could think of 2 possible solutions:
 
1. Use Stunnel from machine-A to machine-B= , and again from machine-B to machine-C.
&nb= sp;
 
2. Use streaming replicat= ion config features to secure traffic (encrypted data over TCP)
 
Master configuration= on machine-A:
=3D>Update replication line in pg_hba.conf to "hostssl"
Slave configuration on machine-B:
=3D>= primary_conninfo=3D'host=3Dmachine-A port=3D5432 sslmode=3Drequire'
or
=3D> primary_conninfo=3D'host=3Dmachine-A port= =3D5432 sslmode=3Dverify-ca'
 
You could then use cascading replication (available from postgres 9.= 2) from machine-B to machine-C.
 
From: hands= free <luke.hansbury@redwood.com>
Sent: Tuesday, May 7, 2013 9:17 AM
Subject: Re: [ADMIN] [SQL] Encrypting P= GBouncer to Postgres DB connections

=0AWe're looking to use streaming replication to a target vi= a a secondary host
using stunnel.  I'd love to hear how you were ab= le to achieve this,
ktm@rice.edu.

Effectively we're looking to have the = database on our customer's site (let's
call that MachineA) replicate to = our backend postgres target in the cloud
(let's call that MachineC).&nbs= p; However, MachineA has no direct communication
with MachineC, in fact,= it should never be allowed to communicate with it.
We have another ser= ver that provides various services to the client MachineA
that is based = in our home datacenter (let's call that MachineB) which we
would like to= use as a 'staging' machine for the replication to the database
replicat= ion target.  Is this possible to achieve using stunnel (and
pgbounc= er?) alone? 

At no point can this traffic go 'in the clear', f= or obvious reasons ;)

Any pointers or assistance help gratefully received!&nbs= p; Thanks



--
View this message in context: http://postgre= sql.1045698.n5.nabble.com/Hot-standby-with-streaming-replication-under-PgSQ= L-9-1-x-failover-when-master-crashes-tp5750442p5754606.html
Sent from th= e PostgreSQL - admin mailing list archive at Nabble.com.


--
Sent via pgsql-admin m= ailing list (pgsql-admin@postgresql.org)
To make ch= anges to your subscription:
http://www.postgresql.org/mailpref/pgsql-adm= in


--48240482-1519852437-1367946428=:1661--