vulnerability/SSL

Поиск
Список
Период
Сортировка
От dong changyu
Тема vulnerability/SSL
Дата
Msg-id 20050608130924.40030.qmail@web52509.mail.yahoo.com
обсуждение исходный текст
Ответы Re: vulnerability/SSL
Список pgsql-general
Hi,
I¡¯m using postgreSQL with SSL these days. The version
I¡¯m using is 8.0.3. I found that it¡¯s impossible to
use an encrypted key file.
When you use a protected server.key file, you will be
prompted to input your passphrase EVERYTIME IT¡¯S
USED, not only when you start the server but also when
a client makes a connection. So you have to leave the
key file un-protected. I think it¡¯s a serious
vulnerability since the security relies on the secrecy
of the private key. Without encryption, the only thing
we can use to protect the private key is the access
control mechanism provided by the OS.
Any comments on this issue?

cheers,
Changyu




__________________________________
Discover Yahoo!
Have fun online with music videos, cool games, IM and more. Check it out!
http://discover.yahoo.com/online.html

В списке pgsql-general по дате отправления:

Предыдущее
От: Howard Cole
Дата:
Сообщение: Re: Backup Compatibility between minor versions.
Следующее
От: Együd Csaba
Дата:
Сообщение: Re: Where to find translation of Postgres error messages?