Re: Trust intermediate CA for client certificates

Поиск
Список
Период
Сортировка
От Stephen Frost
Тема Re: Trust intermediate CA for client certificates
Дата
Msg-id 20131202215656.GZ17272@tamriel.snowman.net
обсуждение исходный текст
Ответ на Re: Trust intermediate CA for client certificates  (Ian Pilcher <arequipeno@gmail.com>)
Ответы Re: Trust intermediate CA for client certificates
Список pgsql-hackers
* Ian Pilcher (arequipeno@gmail.com) wrote:
> > In any case, the idea that this is somehow OpenSSL's fault and another
> > implementation of the same protocol wouldn't have the same issue sounds
> > pretty silly.
>
> Actually other implementations do this.  In fact, a flag was added to
> OpenSSL fairly recently to allow validating a chain only up to an
> intermediate CA for this very reason.

Perhaps that's been a recent change, but it certainly wasn't part of the
original approach and complaining that PG doesn't do it is hardly fair.
Indeed, it sounds like this is something which should *still* be done
outside of PG and through however you configure OpenSSL on your system.

Regardless, it's completely off-topic for this discussion, which is
about documenting what we *currently* do.  If you'd like to propose a
new set of features, or better yet, a rework of how we configure SSL in
PG, please do so on another thread. :)
Thanks!
    Stephen

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Stephen Frost
Дата:
Сообщение: Re: Extension Templates S03E11
Следующее
От: Peter Eisentraut
Дата:
Сообщение: Re: Fwd: Re: [BUGS] BUG #7873: pg_restore --clean tries to drop tables that don't exist