Re: PKI/SSL Client/Server Certificate Authentication

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: PKI/SSL Client/Server Certificate Authentication
Дата
Msg-id 25602.1137168524@sss.pgh.pa.us
обсуждение исходный текст
Ответ на PKI/SSL Client/Server Certificate Authentication  ("Brian A. Seklecki" <lavalamp@spiritual-machines.org>)
Ответы Re: PKI/SSL Client/Server Certificate Authentication  ("Brian A. Seklecki" <lavalamp@spiritual-machines.org>)
Список pgsql-admin
"Brian A. Seklecki" <lavalamp@spiritual-machines.org> writes:
> If a "bad person" were to somehow obtain a copy of the source code with a
> password embedded in the connect string (Steal it from a developer who
> uses Windows, or maybe convince Apache to not interpret PHP before sending
> to the client, something stupid like that), they would still be unable to
> connect without a client certificate.

So they steal the client certificate file instead of (the file
containing) the password.  How exactly is this more secure?

            regards, tom lane

В списке pgsql-admin по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: [GENERAL] Problem with restoring database from 7.3.1 to 8.0.1
Следующее
От: "Brian A. Seklecki"
Дата:
Сообщение: Re: PKI/SSL Client/Server Certificate Authentication