1 of 24

Kshetrapaldesi TUtika

2 of 24

Agenda

User management: Roles and privileges

  • Public role
  • Public schema
  • Best practices public role/schema
  • Column level security
  • Improved role management

Authentication and Security

- SCRAM_SHA-256 based authentication

  • LDAP authentication
  • GSSAPI encryption
  • Enhanced password policies
  • Direct TLS Handshake
  • Incremental backup support

3 of 24

User management: Roles and privileges

4 of 24

5 of 24

6 of 24

Public schema security (Version < 15)

7 of 24

8 of 24

Public schema security (Version >= 15)

9 of 24

Create a table in public schema (<15 vs >=14)

10 of 24

Best practices on public schema/role

REVOKE CREATE ON SCHEMA public FROM PUBLIC;

REVOKE USAGE ON SCHEMA public FROM PUBLIC;

REVOKE CONNECT ON DATABASE your_database_name FROM PUBLIC;

11 of 24

12 of 24

13 of 24

Authentication and encryption

14 of 24

15 of 24

16 of 24

host <database> <user> <ip-address>/<subnet> gss

17 of 24

18 of 24

����PostgreSQL's TLS security features from version 10 through version 17:

19 of 24

psql "host=your_server dbname=your_database user=your_user sslmode=require sslnegotiation=direct"

20 of 24

21 of 24

22 of 24

Conclusion

23 of 24

Talks by our Microsoft team

Shreya Aithal

Fri Aug 22 | 11:10am

Agents, Agents Everywhere, But Still a Mystery to Most

Kshetrapaldesi Tutika

Fri Aug 22 | 4:10 pm

Making PostgreSQL More Secure – A Journey from Version 10 to 17

Shreya Aithal

Fri Aug 22 | 5:00pm

PostgreSQL at Microsoft: Contributions, Community, and Cloud

24 of 24

Save the date

Coming soon…

A free & virtual developer event

PosetteConf.com

Check out the schedule 🡪

Now in its 5th year!