Re: LDAP(s) doc misleading

2021-01-07 Thread Paul Förster
Hi Magnus, > On 07. Jan, 2021, at 11:04, Magnus Hagander wrote: > > No, I think this is correct. > > "Set to ldaps to use ldaps" means you set it to the value "ldaps" in > order to use ldaps. > > I think you missed the "to" in the sentence -- without that one, your > reading of it would make m

Re: LDAP(s) doc misleading

2021-01-07 Thread Magnus Hagander
On Wed, Jan 6, 2021 at 8:36 AM Paul Förster wrote: > > Hi, > > I found what I believe to be misleading in the LDAP documentation: > > https://www.postgresql.org/docs/current/auth-ldap.html > > It says: > "ldapscheme > Set to ldaps to use LDAPS."... > > IMHO, it should say: > "ldapscheme > Set to l

Re: LDAP(s) doc misleading

2021-01-07 Thread Paul Förster
Hi Stephen, > On 06. Jan, 2021, at 18:14, Stephen Frost wrote: > > When in an Active Directory environment, it's far more secure to use > Kerberos/GSSAPI and not LDAP (or LDAPS). Using the ldap authentication > method with PostgreSQL will result in the credentials of users being > sent to the d

Re: LDAP(s) doc misleading

2021-01-06 Thread Stephen Frost
Greetings, * Paul Förster (paul.foers...@gmail.com) wrote: > I found this because I'm in the process of making our Linux LDAP servers > obsolete by reconfiguring PostgreSQL to use our company Windows Active > Directory LDAPS service. When in an Active Directory environment, it's far more secure