Re: Automatic CRL reload

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: Automatic CRL reload
Дата
Msg-id 20081227141017.GB3847@alvh.no-ip.org
обсуждение исходный текст
Ответ на Automatic CRL reload  (Andrej Podzimek <andrej@podzimek.org>)
Ответы Re: Automatic CRL reload  (Bruce Momjian <bruce@momjian.us>)
Список pgsql-general
Andrej Podzimek wrote:

> "The files server.key, server.crt, root.crt, and root.crl are only
> examined during server start; so you must restart the server for
> changes in them to take effect."
> (http://www.postgresql.org/docs/8.3/static/ssl-tcp.html)
>
> This is perfectly fine for server.key, server.crt and root.crt. These
> files change quite rarely. However, root.crl usually chages once a
> month (which is the default in OpenSSL) or even more often when
> necessary.

I think the right solution here is to reload the CRL file on SIGHUP
(reload).  Whoever changes the CRL file should send a signal.

I've had that on my TODO list for a while.

--
Alvaro Herrera                                http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.

В списке pgsql-general по дате отправления:

Предыдущее
От: Ivan Sergio Borgonovo
Дата:
Сообщение: subselect and count (DISTINCT expression [ , ... ] ) performances
Следующее
От: "Jeffrey Melloy"
Дата:
Сообщение: Weird query sort