Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS

Поиск
Список
Период
Сортировка
От Andreas Pflug
Тема Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS
Дата
Msg-id 481EF236.7080000@pse-consulting.de
обсуждение исходный текст
Ответ на Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS  (David Boreham <david_list@boreham.org>)
Список pgsql-hackers
Tom Lane wrote:
> stephen layland <steve@68k.org> writes:
>   
>> I've written a quick patch against the head branch (8.4DEV, but it also
>> works with 8.1.3 sources) to fix LDAP authentication support to
>> work with LDAPS servers that do not need start TLS.   I'd be interested
>> to hear your opinions on this.
>>     
>
> Not being an LDAP user, I'm not very qualified to comment on the details
> here, but ...
>
>   
>>     My solution was to create a boolean config variable called
>>     ldap_use_start_tls which the user can toggle whether or not
>>     start tls is necessary.
>>     
>
> ... I really don't like using a GUC variable to determine the
> interpretation of entries in pg_hba.conf.  A configuration file exists
> to set configuration, it shouldn't need help from a distance.  Also,
> doing it this way means that if several different LDAP servers are
> referenced in different pg_hba.conf entries, they'd all have to have
> the same encryption behavior.
>
> I think a better idea is to embed the flag in the pg_hba.conf entry
> itself.  Perhaps something like "ldapso:" instead of "ldaps:" to
> indicate "old" secure ldap protocol, or include another parameter
> in the URL body.
>   
With ldaps on port 636 STARTTLS should NEVER be issued, so the protocol 
identifier ldaps should be sufficient as "do not issue STARTTLS" flag. 
IMHO the current pg_hba.conf implementation doesn't follow the usual 
nomenclatura; ldap with TLS is still ldap. Using ldaps as indicator for 
ldap with tls over port 389 is misleading for anyone familiar with ldap.

Regards,
Andreas



В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Zeugswetter Andreas OSB sIT"
Дата:
Сообщение: Re: statement timeout vs dump/restore
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS