List:Internals« Previous MessageNext Message »
From:Sasha Pachev Date:February 15 2001 8:00pm
Subject:Re: transparent query direction
View as plain text  
On Thursday 15 February 2001 12:47, Paul Repacholi wrote:
>> If the slave can update the master by proxy, security-wise this is
>> equivalent to anybody who connects to the slave being able to do
>> anything a replication user can on the master. So in that case, this
>> is the same as connecting directly to the master anyway with slave
>> user privileges.
>
>This is totaly wrong. Via the slave gives ONLY MySQL access, and that
>may well be restricted as well. It give NO access to any other net
>traffic at all.
>
>That is why it is liked, and required in some cases by security.

How is it more secure that just opening MySQL port on the master, and 
restricting the privileges inside MySQL on the master? The only extra benefit 
I see is that you cannot exploit the protocol vulnerabilities on a low level. 
Otherwise, you can run all the same queries by proxy through the slave as you 
would directly on the master.

-- 
MySQL Development Team
   __  ___     ___ ____  __ 
  /  |/  /_ __/ __/ __ \/ /   Sasha Pachev <sasha@stripped>
 / /|_/ / // /\ \/ /_/ / /__  MySQL AB, http://www.mysql.com/
/_/  /_/\_, /___/\___\_\___/  Provo, Utah, USA
       <___/                  
Thread
transparent query directionHroi Sigurdsson14 Feb
  • Re: transparent query directionRussell E Glaue14 Feb
  • Re: transparent query directionSasha Pachev15 Feb
    • Re: transparent query directionHroi Sigurdsson15 Feb
      • Re: transparent query directionPaul Repacholi15 Feb
      • Re: transparent query directionSasha Pachev15 Feb
    • Re: transparent query directionJeremy D. Zawodny15 Feb
      • Re: transparent query directionSasha Pachev15 Feb
        • Re: transparent query directionPaul Repacholi15 Feb
          • Re: transparent query directionSasha Pachev15 Feb
            • Re: transparent query directionPaul Repacholi16 Feb
        • Re: transparent query directionJeremy D. Zawodny21 Feb
          • Re: transparent query directionSasha Pachev21 Feb
            • Re: transparent query directionHroi Sigurdsson21 Feb
              • Re: transparent query directionSasha Pachev21 Feb
                • Re: transparent query directionHroi Sigurdsson21 Feb
                  • Re: transparent query directionSasha Pachev22 Feb
                    • Re: transparent query directionMichael Widenius3 Mar
                      • Re: transparent query directionSasha Pachev5 Mar
  • Re: transparent query directionPaul Cadach5 Mar
    • Re: transparent query directionSasha Pachev5 Mar
  • Re: transparent query directionPaul Cadach5 Mar
    • Re: transparent query directionSasha Pachev5 Mar
  • Re: transparent query directionPaul Cadach6 Mar
  • Re: transparent query directionPaul Cadach7 Mar
  • Re: transparent query directionPaul Cadach7 Mar
  • Re: transparent query directionPaul Cadach7 Mar
Re: transparent query directionMichael Widenius5 Mar
Re: transparent query directionHeikki Tuuri7 Mar