Re: How to configure client-side TLS ciphers for streaming replication?

Поиск
Список
Период
Сортировка
От Laurenz Albe
Тема Re: How to configure client-side TLS ciphers for streaming replication?
Дата
Msg-id a38653565ad81ced7480f810bbe02918c5ee6cbf.camel@cybertec.at
обсуждение исходный текст
Ответ на Re: How to configure client-side TLS ciphers for streaming replication?  (xx Z <xxz030811@gmail.com>)
Ответы Re: How to configure client-side TLS ciphers for streaming replication?
Список pgsql-general
On Tue, 2025-08-26 at 20:34 +0800, xx Z wrote:
> Thanks for your suggestion.
> But I still want to know why we can't set "ssl_ciphers" on the client side.

I'd say because nobody implemented it, perhaps because nobody felt the need.

> This is still considered a security issue in some cases, and PostgreSQL has
> mature capabilities on the master side to implement this functionality.

That sounds to me like some moderately clueful security auditor is looking
for a nit to pick.  If you do streaming replication, and you control the
ciphers on the primary server, what added security benefit do you get by
controlling the ciphers on the standby server (the client) as well?

Yours,
Laurenz Albe



В списке pgsql-general по дате отправления: