Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1myGhj-0006Wg-Im for pgsql-sql@arkaria.postgresql.org; Fri, 17 Dec 2021 17:07:36 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1myGhi-0000bY-Ea for pgsql-sql@arkaria.postgresql.org; Fri, 17 Dec 2021 17:07:34 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1myGhi-0000bP-51 for pgsql-sql@lists.postgresql.org; Fri, 17 Dec 2021 17:07:34 +0000 Received: from mout.gmx.net ([212.227.17.21]) by magus.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1myGhg-0000L3-5y for pgsql-sql@lists.postgresql.org; Fri, 17 Dec 2021 17:07:33 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1639760850; bh=riPMXbEAImfmicF/N1pvrPmow+/dBCfU6xbExzvaFG4=; h=X-UI-Sender-Class:Subject:To:References:From:Date:In-Reply-To; b=KwCd6yDa7l3EPEJn5NdppzkNE8KqsmHdxmV1LxThuJwzKP37xV6XYUoJeF+924Zqb Cs7tGVc9Z/xDIJigPlZFwGrnJtNeoiwe3bszlry/cBsLV9zARMGFFMhtHGoqWFsX+z F+35qfDNpBHxd2SNBBYH8KtwlMuFGiTmR3o8e3nI= X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c Received: from [192.168.178.20] ([83.171.161.74]) by mail.gmx.net (mrgmx104 [212.227.17.168]) with ESMTPSA (Nemesis) id 1Mnaof-1mFLVv09Z7-00je7J for ; Fri, 17 Dec 2021 18:07:30 +0100 Subject: Re: Pragma autonomous transactions in Postgres/ Certification based authentication in DB Links To: pgsql-sql@lists.postgresql.org References: <1355149.1639758450@sss.pgh.pa.us> From: Thomas Kellerer Message-ID: Date: Fri, 17 Dec 2021 18:07:29 +0100 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.1.21) Gecko/20090302 Thunderbird/2.0.0.21 Mnenhy/0.7.5.666 MIME-Version: 1.0 In-Reply-To: <1355149.1639758450@sss.pgh.pa.us> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: de-DE Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K1:/4me3G3+wdiP0QDSb/sgflXF24TwDZMVPxWFyleg2FzTja/rKtt n7oISqdFGjfIWA0TiQmrhlNYV/T/RmSII68yF5AcfpZd8SVRVksEGZhXXdePplFLtS5wVv+ UkChtujG9/P1Fybie4whdCPkfnZG3bZRsH7N9okcCCsBxQWD5TZqdLfbeGZ+rMKyXBgTg5U TRn3vgoRJGHDWeAdPs12A== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V03:K0:K4pLAxIeuxM=:7Bxaz9THOCFhaF+V8YqXm+ UIpmYSyPiBzWFQFgYPLNN7SO9KQCv/HqMqhP9O2X4fPbhQ1mkY+wA5NkWsWsMWiTtaR4tqRFe 8iMXZT/hZwtm46AWgQC3RMaJHhscSHn0rrzcTCbOW2srpkrbVYeAoo/YPfoBegNxB3TFFffOP NYyibIXwcVOvb7b8WDvxUNR8n7SvzPzCihjd9yladqcSmS4MrEloZMC14cTwWf6UeXMQb5x0N rkw9rgIC07HzGlCWr61dMsV8HN6G5m50fiSMqt2AFDR+DZWVDTb9LIw41S3L3snc+Ph4i2eJk LJU44E0SXmj2BOTxtPHLVfAtpzWrijMw4eu4xPky/0d+ldDoUI4eu9TubLv1GRI3x9cTl/9O3 V88W3AsLKI6aG4vHLz384ylB1OaZUEZrJMKzNqAQkoE2/smCo9ffMXrCwMQQ527oxRe7fz+uf bflBLL4IHz+vuuZpmTFKysFSSAdKy6lc+rLVPyzJy5BfVsbTTaxr3zkdhbgzq04xH6Fy6/heN MaKrQR5u0asOHGDVCDL3U1HLxTRL16vdMnn1wfX7KBC/i6+dAjDLoaYtnsuQb+a2Niia09Xbf wCDE5f2m/tVonOUQRJTEn/2K1PeZiuHCSDHNAvxaOc80G51QOeS8t58aV+jQBpf5V3q4XwlF1 LXoXbkKIM8WGz61q5T3LJfVv3EoL6ueGA5fTW7LDlwMS2dGkJ7khHWWU04dHxnZb9j7jSBZxZ 4hh2b85k/PD/xVNtyqMMpFBwpP2kXbjz5wqKiONI/Tx5J8MrVwZfWSi1+uUD+BM6uC69TnGhF vyDYf7kCLrSJ3+UbqAk4ae9/8tsTrovdEBfyvch+dZl4eGRuwEnL2gY75j+hv9Bm+8zh3g2EM JX22N0ClZeTsi5eGbtM5EBF0w7HhEyrxT2Fj+omigBJx4yg+lEmnEwWKUdKmOF87jzmvcXouE FmjtmpCxFIz42igO89mi5974M6IQvL+ycB7hWUXGZJUwRpZ5un/Wdjo7jwl1iRdxkXaHz7B9A jNeTTmDd7YIwAc7+CRA84EuxTCCrobXHKMJM4OBYrTa5fJHhwYZb3n5IZbJIz+ETIfjrgOrrz QPaMPi/gLlf4+s= List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Tom Lane schrieb am 17.12.2021 um 17:27: > No, that won't help. Like postgres_fdw, dblink will only let you use > non-password auth methods if you're superuser [1][2]. The problem is > that making use of any credentials stored in the server's filesystem > amounts to impersonating the OS user that's running the server. It'd > be nice to find a less confining solution, but I'm not sure what one > would look like. > > Maybe "use server's FDW credentials" could be associated with a > grantable role? That's still an awfully coarse-grained approach > though. I thought for a moment about putting an SSL cert right > into the connection string; but you'd have to put the SSL private > key in there too, making it just as much of a security problem as > putting a password there (but about 100 times more verbose :-(). What about using a .pgpass file? We use that to hide the password for FDW connections on the SQL level. Regards Thomas