From 996832caeec19ed43fdc36db33ae7ee48e348662 Mon Sep 17 00:00:00 2001 From: Peter Eisentraut Date: Fri, 25 Aug 2000 10:00:35 +0000 Subject: Make the location of the Kerberos server key file run time configurable (rather than compile time). For libpq, even when Kerberos support is compiled in, the default user name should still fall back to geteuid() if it can't be determined via the Kerberos system. A couple of fixes for string type configuration parameters, now that there is one. --- doc/src/sgml/client-auth.sgml | 18 ++++++++++-------- doc/src/sgml/installation.sgml | 18 ++---------------- doc/src/sgml/runtime.sgml | 12 +++++++++++- 3 files changed, 23 insertions(+), 25 deletions(-) (limited to 'doc/src') diff --git a/doc/src/sgml/client-auth.sgml b/doc/src/sgml/client-auth.sgml index f22b0af662..31d910b302 100644 --- a/doc/src/sgml/client-auth.sgml +++ b/doc/src/sgml/client-auth.sgml @@ -1,4 +1,4 @@ - + Client Authentication @@ -341,7 +341,7 @@ host all 192.168.2.0 255.255.255.0 ident othermap - + Kerberos authentication @@ -369,13 +369,15 @@ host all 192.168.2.0 255.255.255.0 ident othermap Postgres should operate like a normal Kerberos service. The name of the service principal is normally postgres, unless it was changed during the - build. Make sure that your server keytab file is readable (and + build. Make sure that your server key file is readable (and preferrably only readable) by the Postgres server account (see - ). The location of the keytab file - is specified at build time; by default it is - /etc/srvtab in Kerberos 4 and - FILE:/usr/local/pgsql/etc/krb5.keytab in - Kerberos 5. + ). The location of the key file + is specified with the krb_server_keyfile run time + configuration parameter. (See also .) + The default is /etc/srvtab if you are using Kerberos 4 + and FILE:/usr/local/pgsql/etc/krb5.keytab (or whichever + directory was specified as sysconfdir at build time) + with Kerberos 5. diff --git a/doc/src/sgml/installation.sgml b/doc/src/sgml/installation.sgml index 63c8dfc189..62ac008083 100644 --- a/doc/src/sgml/installation.sgml +++ b/doc/src/sgml/installation.sgml @@ -1,4 +1,4 @@ - + <![%flattext-install-include[<productname>PostgreSQL</> ]]>Installation Instructions @@ -577,27 +577,13 @@ su - postgres - - --with-krb-srvtab=FILE - - - Specifies the location of the Kerberos server shared key file - (srvtab). If you are using Kerberos 4, this - defaults to /etc/srvtab, with Kerberos 5 to - FILE:/usr/local/pgsql/etc/krb5.keytab, or - equivalent, depending on what you set - - - --enable-syslog Enables the PostgreSQL server to use the syslog logging facility. (Using this option does not mean - that you have to log with syslog or even that it will be done + that you will have to log with syslog or even that it will be done by default, it simply makes it possible to turn this option on at run time.) diff --git a/doc/src/sgml/runtime.sgml b/doc/src/sgml/runtime.sgml index ada29b5b60..c7654c5d73 100644 --- a/doc/src/sgml/runtime.sgml +++ b/doc/src/sgml/runtime.sgml @@ -1,5 +1,5 @@ @@ -898,6 +898,16 @@ env PGOPTIONS='--geqo=off' psql + + KRB_SERVER_KEYFILE + + + Sets the location of the Kerberos server key file. See + for details. + + + + MAX_CONNECTIONS (integer) -- cgit v1.2.1