Re: RFC 9266: Channel Bindings for TLS 1.3 support
| От | Jacob Champion |
|---|---|
| Тема | Re: RFC 9266: Channel Bindings for TLS 1.3 support |
| Дата | |
| Msg-id | CAOYmi+k0N+fcrW=xz_bshwzjM5CkSFUzKjTa+xeoyohkXD8doQ@mail.gmail.com обсуждение исходный текст |
| Ответ на | Re: RFC 9266: Channel Bindings for TLS 1.3 support (Heikki Linnakangas <hlinnaka@iki.fi>) |
| Ответы |
Re: RFC 9266: Channel Bindings for TLS 1.3 support
Re: RFC 9266: Channel Bindings for TLS 1.3 support |
| Список | pgsql-hackers |
On Thu, Nov 20, 2025 at 1:52 PM Heikki Linnakangas <hlinnaka@iki.fi> wrote: > PostgreSQL does support channel binding, with tls-server-end-point. I > believe that sufficient to prevent an attack like that. No, IIRC unique bindings (-unique and -exporter) prevent MITM even if the attacker has the server's private key, as long as they do not also possess the SCRAM verifiers. tls-server-end-point does not prevent against that (so you can terminate TLS on a different node from the verifiers). --Jacob
В списке pgsql-hackers по дате отправления: