Re: Update minimum SSL version

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: Update minimum SSL version
Дата
Msg-id 7e217273-b550-96e5-f36f-a818ac4b5d9b@2ndquadrant.com
обсуждение исходный текст
Ответ на Re: Update minimum SSL version  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Update minimum SSL version  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
On 2019-11-30 04:06, Tom Lane wrote:
> I think the real question we have to answer is this: are we intent on
> making people upgrade ancient openssl installations?  If so, shouldn't
> we be doing something even more aggressive than this?  If not, wouldn't
> the patch need to try to autoconfigure the minimum TLS version?  As
> proposed, the patch seems to be somewhere in a passive-aggressive middle
> ground of being annoying without really enforcing anything.  So I don't
> quite see the point.

The trade-off is that this makes the defaults better for the vast 
majority of users and gives users of really old systems a nudge that 
they are no longer in compliance with industry best practices.  You need 
manual steps to set up SSL anyway, so this doesn't introduce an entirely 
new kind of requirement for the latter group of users.

-- 
Peter Eisentraut              http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Update minimum SSL version
Следующее
От: Etsuro Fujita
Дата:
Сообщение: Re: Bogus EXPLAIN results with column aliases for mismatched partitions