SSL (patch 6) - Mailing list pgsql-patches

From Bear Giles
Subject SSL (patch 6)
Date
Msg-id 200205250624.AAA25681@eris.coyotesong.com
Whole thread Raw
Responses Re: SSL (patch 6)  (Bruce Momjian <pgman@candle.pha.pa.us>)
Re: SSL (patch 6)  (Bruce Momjian <pgman@candle.pha.pa.us>)
List pgsql-patches
SSL support for ephemeral DH keys.

As the comment headers in be-secure.c discusses, EPH preserves
confidentiality even if the static private key (which is usually
kept unencrypted) is compromised.

Because of the value of this, common default values are hard-coded
to protect the confidentiality of the data even if an attacker
successfully deletes or modifies the external file.

Bear

Attachment

pgsql-patches by date:

Previous
From: Bear Giles
Date:
Subject: SSL (patch 5)
Next
From: Bear Giles
Date:
Subject: SSL (patch 7)