Re: Experiments with Postgres and SSL

Поиск
Список
Период
Сортировка
От Vladimir Sitnikov
Тема Re: Experiments with Postgres and SSL
Дата
Msg-id CAB=Je-EPYPC2fN7J11PPQM0Q_-nDfnxvCr1An6TdX+sPJSnJsQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Experiments with Postgres and SSL  (Greg Stark <stark@mit.edu>)
Ответы Re: Experiments with Postgres and SSL  (Greg Stark <stark@mit.edu>)
Список pgsql-hackers
It would be great if PostgreSQL supported 'start with TLS', however, how could clients activate the feature?

I would like to refrain users from configuring the handshake mode, and I would like to refrain from degrading performance when a new client talks to an old database.

What if the server that supports 'fast TLS' added an extra notification in case client connects with a classic TLS?
Then a capable client could remember host:port and try with newer TLS appoach the next time it connects.

It would be transparent to the clients, and the users won't need to configure 'prefer classic or fast TLS'
The old clients could discard the notification.

Vladimir

--
Vladimir

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Jacob Champion
Дата:
Сообщение: Re: Transparent column encryption
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: document the need to analyze partitioned tables