Re: Supporting Windows SChannel as OpenSSL replacement

Поиск
Список
Период
Сортировка
От Heikki Linnakangas
Тема Re: Supporting Windows SChannel as OpenSSL replacement
Дата
Msg-id 5395C743.7000809@vmware.com
обсуждение исходный текст
Ответ на Re: Supporting Windows SChannel as OpenSSL replacement  (Andres Freund <andres@2ndquadrant.com>)
Ответы Re: Supporting Windows SChannel as OpenSSL replacement
Список pgsql-hackers
On 06/09/2014 05:22 PM, Andres Freund wrote:
> Hi,
>
> On 2014-06-09 10:18:40 -0400, Tom Lane wrote:
>> Does SChannel have a better security track record than OpenSSL?  Or is
>> the point here just that we can define it as not our problem when a
>> vulnerability surfaces?
>
> Well, it's patched as part of the OS - so no new PG binaries have to be
> released when it's buggy.

Right. I have no idea what SChannel's track record is, but when there's 
a vulnerability in the native SSL implementation in Windows, you better 
upgrade anyway, regardless of PostgreSQL. So when we rely on that, we 
don't put any extra burden on users. And we won't need to release new 
binaries just to update the DLL included in it.

- Heikki



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Martijn van Oosterhout
Дата:
Сообщение: Re: Supporting Windows SChannel as OpenSSL replacement
Следующее
От: Andres Freund
Дата:
Сообщение: Re: Inaccuracy in VACUUM's tuple count estimates