Re: SSL configure patch: review - Mailing list pgsql-hackers

From Alvaro Herrera
Subject Re: SSL configure patch: review
Date
Msg-id 20081121141314.GB5210@alvh.no-ip.org
Whole thread Raw
In response to Re: SSL configure patch: review  (Magnus Hagander <magnus@hagander.net>)
Responses Re: SSL configure patch: review  (Magnus Hagander <magnus@hagander.net>)
List pgsql-hackers
Magnus Hagander escribió:
> Alex Hunsaker wrote:
> > On Fri, Aug 1, 2008 at 13:31, Alvaro Herrera <alvherre@commandprompt.com> wrote:
> >> Something that's bothering me is that PGSSLKEY is inconsistent with the
> >> sslkey conninfo parameter.  PGSSLKEY specifies an engine (basically a
> >> driver for specialized hardware AFAICT) from which the key is to be
> >> loaded, but sslkey is a simple filename.  This means that there's no way
> >> to load a key from hardware if you want to specify it per connection.
> >> Not that I have any such hardware, but it looks bogus.

I think the above consideration needs some discussion too.  Committing
it as-is doesn't seem OK because you can't change it later -- it's
user-visible.

-- 
Alvaro Herrera                                http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.


pgsql-hackers by date:

Previous
From: Magnus Hagander
Date:
Subject: Re: Autoconf, libpq and replacement function
Next
From: Magnus Hagander
Date:
Subject: Re: SSL configure patch: review