Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS

Поиск
Список
Период
Сортировка
От David Boreham
Тема Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS
Дата
Msg-id 481F0D4D.4070103@boreham.org
обсуждение исходный текст
Ответ на Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS  (Andreas Pflug <pgadmin@pse-consulting.de>)
Ответы Re: Proposed Patch - LDAPS support for servers on port 636 w/o TLS  (steve layland <steve@68k.org>)
Список pgsql-hackers
Andreas Pflug wrote:
> With ldaps on port 636 STARTTLS should NEVER be issued, so the 
> protocol identifier ldaps should be sufficient as "do not issue 
> STARTTLS" flag. IMHO the current pg_hba.conf implementation doesn't 
> follow the usual nomenclatura; ldap with TLS is still ldap. Using 
> ldaps as indicator for ldap with tls over port 389 is misleading for 
> anyone familiar with ldap.
I agree. ldaps:: should mean plain SSL without StartTLS. ldap:: should 
mean a plain text connection,
unless some additional configuration directive enables StartTLS.

There has been some discussion in the past about including (or not) this 
configuration state in the url :

http://www.openldap.org/lists/openldap-devel/200202/msg00070.html




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Andrew Dunstan
Дата:
Сообщение: Re: statement timeout vs dump/restore
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Protection from SQL injection