Re: SCRAM with channel binding downgrade attack

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: SCRAM with channel binding downgrade attack
Дата
Msg-id 20180628124829.GA6260@momjian.us
обсуждение исходный текст
Ответ на Re: SCRAM with channel binding downgrade attack  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-hackers
On Thu, Jun 28, 2018 at 09:35:57AM +0200, Magnus Hagander wrote:
> No, we absolutely still have SCRAM channel binding.
> 
> *libpq* has no way to *enforce* it, meaning it always acts like our default SSL
> config which is "use it if available but if it's not then silently accept the
> downgrade". From a security perspective, it's just as bad as our default ssl
> config, but unlike ssl you can't configure a requirement in 11.

I think we are much more likely to be able to force channel binding by
default since there is no need to configure a certificate authority.

-- 
  Bruce Momjian  <bruce@momjian.us>        http://momjian.us
  EnterpriseDB                             http://enterprisedb.com

+ As you are, so once was I.  As I am, so you will be. +
+                      Ancient Roman grave inscription +


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Isaac Morland
Дата:
Сообщение: Re: Unexpected behavior of DROP VIEW/TABLE IF EXISTS
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: SCRAM with channel binding downgrade attack