Re: Feature request: A method to configure client-side TLS ciphers for streaming replication

Поиск
Список
Период
Сортировка
От Ron Johnson
Тема Re: Feature request: A method to configure client-side TLS ciphers for streaming replication
Дата
Msg-id CANzqJaBirEU9ZNZdSSPKRW7Hm9LrXCYOcH62=bppzOr6-AvGVg@mail.gmail.com
обсуждение исходный текст
Ответ на Feature request: A method to configure client-side TLS ciphers for streaming replication  (xx Z <xxz030811@gmail.com>)
Ответы Re: Feature request: A method to configure client-side TLS ciphers for streaming replication
Список pgsql-general
On Tue, Aug 26, 2025 at 3:28 AM xx Z <xxz030811@gmail.com> wrote:
Hello PostgreSQL community,

I have a question regarding the configuration of streaming replication.

When setting up streaming replication over TLS, I've noticed that while the primary server can restrict its supported encryption algorithms using the ssl_ciphers parameter, there doesn't seem to be a corresponding method for the standby (client) side of the replication connection. The standby appears to use all the default ciphers supported by the system's OpenSSL library.

What is a "standby (client)"?

Postgresql version: 15.2

That's missing 12 sets (three years) of bug fixes.  When using RPM or .deb packages, updating takes only a few minutes.

--
Death to <Redacted>, and butter sauce.
Don't boil me, I'm still alive.
<Redacted> lobster!

В списке pgsql-general по дате отправления: