Re: How to configure client-side TLS ciphers for streaming replication?
От
Laurenz Albe
Тема
Re: How to configure client-side TLS ciphers for streaming replication?
Дата
Msg-id
a38653565ad81ced7480f810bbe02918c5ee6cbf.camel@cybertec.at
Ответ на
Список
Дерево обсуждения
How to configure client-side TLS ciphers for streaming replication? xx Z <xxz030811@gmail.com>
Re: How to configure client-side TLS ciphers for streaming replication? Laurenz Albe <laurenz.albe@cybertec.at>
Re: How to configure client-side TLS ciphers for streaming replication? xx Z <xxz030811@gmail.com>
Re: How to configure client-side TLS ciphers for streaming replication? Rob Sargent <robjsargent@gmail.com>
Re: How to configure client-side TLS ciphers for streaming replication? "DINESH NAIR" <Dinesh_Nair@iitmpravartak.net>
Re: How to configure client-side TLS ciphers for streaming replication? Laurenz Albe <laurenz.albe@cybertec.at>
Re: How to configure client-side TLS ciphers for streaming replication? Daniel Gustafsson <daniel@yesql.se>
On Tue, 2025-08-26 at 20:34 +0800, xx Z wrote: > Thanks for your suggestion. > But I still want to know why we can't set "ssl_ciphers" on the client side. I'd say because nobody implemented it, perhaps because nobody felt the need. > This is still considered a security issue in some cases, and PostgreSQL has > mature capabilities on the master side to implement this functionality. That sounds to me like some moderately clueful security auditor is looking for a nit to pick. If you do streaming replication, and you control the ciphers on the primary server, what added security benefit do you get by controlling the ciphers on the standby server (the client) as well? Yours, Laurenz Albe
В списке pgsql-general по дате отправления