Re: Recent vendor SSL renegotiation patches break PostgreSQL

Поиск
Список
Период
Сортировка
От Stefan Kaltenbrunner
Тема Re: Recent vendor SSL renegotiation patches break PostgreSQL
Дата
Msg-id 4B69934D.7060307@kaltenbrunner.cc
обсуждение исходный текст
Ответ на Re: Recent vendor SSL renegotiation patches break PostgreSQL  (Robert Haas <robertmhaas@gmail.com>)
Ответы Re: Recent vendor SSL renegotiation patches break PostgreSQL  (Chris Campbell <chris_campbell@mac.com>)
Список pgsql-hackers
Robert Haas wrote:
> On Wed, Feb 3, 2010 at 6:24 AM, Chris Campbell <chris_campbell@mac.com> wrote:
>> The flurry of patches that vendors have recently been making to OpenSSL to address
>> the potential man-in-the-middle attack during SSL renegotiation have disabled SSL
>> renegotiation altogether in the OpenSSL libraries. Applications that make use of SSL
>> renegotiation, such as PostgreSQL, start failing.
> 
> Should we think about adding a GUC to disable renegotiation until this
> blows over?

hmm I wonder if we should not go as far as removing the whole 
renegotiation code, from the field it seems that there are very very few 
daemons actually doing that kind forced renegotiation.


Stefan


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: Recent vendor SSL renegotiation patches break PostgreSQL
Следующее
От: Robert Haas
Дата:
Сообщение: Re: Largeobject Access Controls (r2460)