Re: [PATCH] Log details for client certificate failures

Поиск
Список
Период
Сортировка
От Graham Leggett
Тема Re: [PATCH] Log details for client certificate failures
Дата
Msg-id 6EE6999E-0174-4B74-AC70-BE13F53E6827@sharp.fm
обсуждение исходный текст
Ответ на Re: [PATCH] Log details for client certificate failures  (Peter Eisentraut <peter.eisentraut@enterprisedb.com>)
Ответы Re: [PATCH] Log details for client certificate failures  (Jacob Champion <jchampion@timescale.com>)
Список pgsql-hackers
On 30 Jun 2022, at 10:43, Peter Eisentraut <peter.eisentraut@enterprisedb.com> wrote:

I wrote that pg_stat_ssl uses the *issuer* plus serial number to identify a certificate.  What your patch shows is the subject and the serial number, which isn't the same thing.  Let's get that sorted out one way or the other.

Quick observation on this one, the string format of an issuer and serial number is defined as a “Certificate Exact Assertion” in RFC 4523.

I added this to httpd a while back:

SSL_CLIENT_CERT_RFC4523_CEA

It would be good to interoperate.

Regards,
Graham

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: [PATCH] Log details for client certificate failures
Следующее
От: Justin Pryzby
Дата:
Сообщение: Re: doc phrase: "inheritance child"