Universal certificate for verify-full ssl connection

Поиск
Список
Период
Сортировка
От Asia
Тема Universal certificate for verify-full ssl connection
Дата
Msg-id 33248361-0791d6468966804d41201953aac7997f@pkn7.m5r2.onet
обсуждение исходный текст
Ответы Re: Universal certificate for verify-full ssl connection
Список pgsql-general
Hi,

I am trying to generate self-signed certificate for full ssl authentication. I need to have universal version of this
certificatefor development purposes (so any client can connect with any postgresql server with ssl on). 
I am using IP while connecting, I mean host=<IP>.

However verify-full connection works only in case "Common Name" in certificate contains only fully qualified IP
address,when I try to set CN as * (asterisk) I receive error: 

server common name "*" does not match hostname "my_ip"

According to the documentation here : http://www.postgresql.org/docs/current/static/libpq-ssl.html

"If the connection is made using an IP address instead of a host name, the IP address will be matched (without doing
anyDNS lookups). " 

Would you please advise what I am doing wrong? Or maybe there is other way to generate wildcard certificate ?

Thanks in advance !

Joanna

В списке pgsql-general по дате отправления:

Предыдущее
От: "Nicholson, Brad (Toronto, ON, CA)"
Дата:
Сообщение: Re: Inspecting a DB - psql or system tables ?
Следующее
От: Andrej Podzimek
Дата:
Сообщение: Re: Regular disk activity of an idle DBMS