Re: OpenSSL key renegotiation with patched openssl

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: OpenSSL key renegotiation with patched openssl
Дата
Msg-id 12085.1259617401@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: OpenSSL key renegotiation with patched openssl  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-hackers
Magnus Hagander <magnus@hagander.net> writes:
> I haven't looked into the details but - is there a point for us to
> remove the requests for renegotiation completely?

The periodic renegotiations are a recommended security measure.
Fixing one hole by introducing a different attack vector doesn't
seem to me to be an improvement.  Also, when would we undo it?
At least with the current situation, there is an incentive for
people to get a corrected version of openssl as soon as possible
(not "patched", since what this patch does is break essential
functionality; but actually fixed).
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: Application name patch - v4
Следующее
От: Jeff Davis
Дата:
Сообщение: Re: New VACUUM FULL