ssl-info, enforcing list of common-names

Поиск
Список
Период
Сортировка
От Craig Perras
Тема ssl-info, enforcing list of common-names
Дата
Msg-id Pine.LNX.4.64.0810011006340.19163@homer24.u.washington.edu
обсуждение исходный текст
Ответы Re: ssl-info, enforcing list of common-names  (Bruce Momjian <bruce@momjian.us>)
Список pgsql-admin
Hi -

A couple things. I noticed that these two functions return NULL (or empty
string):

select ssl_issuer_dn();
select ssl_client_dn();

However, I can get specific fields:

select '/CN=' || ssl_issuer_field('commonName')
   || '/C=' || ssl_issuer_field('countryName')
   || '/O=' || ssl_issuer_field('organizationName')
   ;

--returns "/CN=UW Services CA/C=US/O=University of Washington"

I'm thinking of using an authorization scheme in which I check a list of
valid certificate common-names, and, if the current client has no cert or
is not in the list, they have no access (maybe force a logout). Is this
feasable and/or advisable? I'll only have a single trusted CA.

Any help is appreciated!

thanks,
--craig

В списке pgsql-admin по дате отправления:

Предыдущее
От: Michael Monnerie
Дата:
Сообщение: Re: [GENERAL] 8.3.4 rpms for Opensuse10.3 64bit
Следующее
От: "Daniel Cristian Cruz"
Дата:
Сообщение: DROP TABLE waiting for pg_dump