PostgreSQL: before and after hardening

Server 18.6 (Debian 18.6-1.pgdg13+2) · collected 2026-10-01T18:03:36Z (before) and 2026-10-01T18:03:37Z (after)

Summary

SeverityBeforeAfter
High110
Medium110
Low00
Checks not evaluated00
CheckTitleBeforeAfter
PG-01Weak pg_hba authentication6 finding(s)pass
PG-02MD5 password hashing1 finding(s)pass
PG-03TLS not enforced2 finding(s)pass
PG-04Unexpected superusers or privileged app role1 finding(s)pass
PG-05pg_hba open to any address1 finding(s)pass
PG-06pgAudit not configured1 finding(s)pass
PG-07Connection logging incomplete3 finding(s)pass
PG-08PUBLIC can create in schema public1 finding(s)pass
PG-09Application role over-privileged4 finding(s)pass
PG-10SECURITY DEFINER without fixed search_path1 finding(s)pass
PG-11Untrusted language marked trustedpasspass
PG-12Sensitive column in plaintext1 finding(s)pass

Findings before hardening

CheckSeverityStatusObjectDetail
PG-01HighFindingpg_hba line 117local all all uses trust.
PG-01HighFindingpg_hba line 119host all all 127.0.0.1 uses trust.
PG-01HighFindingpg_hba line 121host all all ::1 uses trust.
PG-01HighFindingpg_hba line 124local replication all uses trust.
PG-01HighFindingpg_hba line 125host replication all 127.0.0.1 uses trust.
PG-01HighFindingpg_hba line 126host replication all ::1 uses trust.
PG-02MediumFindingclinic_appPassword stored as an MD5 hash.
PG-03HighFindingsslSSL is off; connections cannot be encrypted.
PG-03HighFindingpg_hba line 128host all all all allows connections without TLS.
PG-04HighFindingclinic_appApp role has CREATEDB.
PG-05MediumFindingpg_hba line 128host all all all accepts clients from any address.
PG-06HighFindingshared_preload_librariespgaudit is not preloaded, so no audit records are written.
PG-07MediumFindinglog_connectionsConnections are not logged.
PG-07MediumFindinglog_disconnectionsDisconnections are not logged.
PG-07MediumFindinglog_line_prefixlog_line_prefix lacks user, database, client.
PG-08MediumFindingclinicPUBLIC has CREATE on schema public.
PG-09MediumFindingpublic.patientsOwned by the app role; an owner can alter or drop it.
PG-09MediumFindingpublic.patients_id_seqOwned by the app role; an owner can alter or drop it.
PG-09MediumFindingpublic.appointmentsOwned by the app role; an owner can alter or drop it.
PG-09MediumFindingpublic.appointments_id_seqOwned by the app role; an owner can alter or drop it.
PG-10HighFindingpublic.patient_countSECURITY DEFINER function without a fixed search_path.
PG-12MediumFindingpublic.patients.national_idStored as text (plaintext); expected pgcrypto-encrypted bytea.

Findings after hardening

CheckSeverityStatusObjectDetail