Re: [HACKERS] PostgreSQL - Weak DH group - Mailing list pgsql-hackers

From Christoph Berg
Subject Re: [HACKERS] PostgreSQL - Weak DH group
Date
Msg-id 20170713171036.6vviogetn24go5rj@msg.df7cb.de
Whole thread Raw
In response to Re: [HACKERS] PostgreSQL - Weak DH group  (Alvaro Herrera <alvherre@2ndquadrant.com>)
List pgsql-hackers
Re: Alvaro Herrera 2017-07-13 <20170713170402.74uuoivrgd3c6tnw@alvherre.pgsql>
> > > Objections to committing this now, instead of waiting for v11?
> > 
> > But I am -1 for the sneak part. It is not the time to have a new
> > feature in 10, the focus is to stabilize.
> 
> But if we were treating it as a security issue, would we backpatch it?
> If we do, then it definitely makes sense to put something in pg10.  I'm
> not sure that this patch is it, though -- perhaps it makes sense to put
> a minimal fix in older branches, and let the new feature wait for pg11?

Making it user-configurable seems pretty minimal to me. Everything
else would probably require lengthy explanations about which file
could hold which contents, and this confusion seems to be part of the
problem.

Fwiw, wouldn't it make sense to recreate the default 2048 DH group as
well, maybe each time a new major is branched?

Christoph



pgsql-hackers by date:

Previous
From: Amit Khandekar
Date:
Subject: Re: [HACKERS] UPDATE of partition key
Next
From: Heikki Linnakangas
Date:
Subject: Re: [HACKERS] PostgreSQL - Weak DH group