Re: Direct SSL connection with ALPN and HBA rules

Поиск
Список
Период
Сортировка
От Daniel Gustafsson
Тема Re: Direct SSL connection with ALPN and HBA rules
Дата
Msg-id F1FE761E-EAB0-4C84-96CC-4AB55E44939D@yesql.se
обсуждение исходный текст
Ответ на Re: Direct SSL connection with ALPN and HBA rules  (Heikki Linnakangas <hlinnaka@iki.fi>)
Список pgsql-hackers
> On 29 Apr 2024, at 21:06, Heikki Linnakangas <hlinnaka@iki.fi> wrote:

> Oh I was not aware sslrootcert=system works like that. That's a bit surprising, none of the other ssl-related
settingsimply or require that SSL is actually used. Did we intend to set a precedence for new settings with that? 

It was very much intentional, and documented, an sslmode other than verify-full
makes little sense when combined with sslrootcert=system.  It wasn't intended
to set a precedence (though there is probably a fair bit of things we can do,
getting this right is hard enough as it is), rather it was footgun prevention.

--
Daniel Gustafsson




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Daniel Gustafsson
Дата:
Сообщение: Re: [PATCH] Fix bug when calling strncmp in check_authmethod_valid
Следующее
От: Alexander Korotkov
Дата:
Сообщение: Re: Removing unneeded self joins