Re: SCRAM with channel binding downgrade attack

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: SCRAM with channel binding downgrade attack
Дата
Msg-id 20180627172415.y2pby7gau77274cm@alvherre.pgsql
обсуждение исходный текст
Ответ на Re: SCRAM with channel binding downgrade attack  (Bruce Momjian <bruce@momjian.us>)
Ответы Re: SCRAM with channel binding downgrade attack  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-hackers
Going over this thread a little bit I'm confused about what is being
proposed.  I think I understand that we no longer think we have have
SCRAM channel binding.  I hope that doesn't mean we don't have SCRAM
itself.  However, in terms of the Postgres release proper, what do we
need to do?  There is still an open item about this, and I had the
impression that if we simply demoted channel binding from a pg11 major
feature to barely a footnote that somebody can implement it with some
hypothetical future JDBC driver that supports the option, then we're
done.

Am I mistaken?

-- 
Álvaro Herrera                https://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Pavel Stehule
Дата:
Сообщение: Re: [HACKERS] proposal: schema variables
Следующее
От: Fujii Masao
Дата:
Сообщение: Re: Speedup of relation deletes during recovery