POSTGRES_PASSWORD is required to be set when using POSTGRES_HOST_AUTH_METHOD=cert
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 38/100
Direzione di ricerca
Inizia da docker-entrypoint.sh, in particolare da docker_verify_minimum_env e pg_setup_hba_conf nelle posizioni collegate, per tracciare come POSTGRES_HOST_AUTH_METHOD viene convalidato e scritto in pg_hba.conf. Definisci l’input supportato per l’autenticazione tramite certificato, incluse eventuali opzioni di autenticazione o il comportamento di hostssl, e considera come verificare il completamento della configurazione risultante.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
I'd like to be able to write a configuration that uses mutual TLS with the auth method cert, which does not require a password and instead enforces that the user is equal to the common name of the authenticated client certificate.
However, the only passwordless auth method permitted by by the docker entrypoint script's docker_verify_minimum_env function is trust:
It seems like adding another case to this check to allow for using certificate-based authentication. One concern I have, though, is that there are auth options as well that may be needed, e.g., looking at the pg_setup_hba_conf function below, it appears that if I want to end up with a pg_hba.conf file with cert clientcert=verify-full, that full string (i.e., including the auth options) would need to be set in the POSTGRES_HOST_AUTH_METHOD environment variable as written. I'm not sure if it would make more sense to add a new environment variable for that purpose? There is also no way that I can identify to use hostssl instead of host, though with cert authentication I'm not sure that actually matters.
- Lingua principale
- Shell
- Stelle
- 2.5k
- Fork
- 1.2k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di docker-library/postgres
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
docker-library/postgres#1420 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
docker-library/postgres#1419 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
docker-library/postgres#1389 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 35/100
docker-library/postgres#1356 · 5 commenti · 7 reazioni ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
docker-library/postgres#1355 · 10 commenti · 11 reazioni ·
Tutte le issue di docker-library/postgres
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
omarchy-menu-keybindings lua bind scan spins at 100% CPU when user config iterates a mocked hl APIAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
omacom/omarchy#14302 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Link Checker ReportForse già presa @keraron l’ha presa oggi. Apertaautomated issue report
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
a2aproject/A2A#2297 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
mattpocock/skills#1165 ·
-
agent-research-finding agent-research-recommend chore ready-for-agent
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
jordansmall/spindrift#4487 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno