Re: "cert" + clientcert=verify-ca in pg_hba.conf? - Mailing list pgsql-hackers

From Kyotaro Horiguchi
Subject Re: "cert" + clientcert=verify-ca in pg_hba.conf?
Date
Msg-id 20200825.110049.765607776821346295.horikyota.ntt@gmail.com
Whole thread Raw
In response to Re: "cert" + clientcert=verify-ca in pg_hba.conf?  (Bruce Momjian <bruce@momjian.us>)
Responses Re: "cert" + clientcert=verify-ca in pg_hba.conf?
List pgsql-hackers
At Mon, 24 Aug 2020 21:49:40 -0400, Bruce Momjian <bruce@momjian.us> wrote in 
> > > Are you saying we should _require_ clientcert=verify-full when 'cert'
> > > authentication is used?  I don't see the point of that --- I just
> > > updated the docs to say doing so was duplicate behavior.
> > 
> > I don't suggest changing the current behavior. I'm saying it is the
> > way it is working and we should correctly error-out that since it
> > doesn't work as specified.

Sorry, I mistead you. I don't suggest verify-full is needed for cert
authentication. I said we should just reject the combination
cert+veriry-ca.

> Uh, I don't understand what 'combination the same way with
> "cert"+"no-verify"'.  Right now, cert with no clientcert/verify line
> works just fine.  Is "no-verify" something special?  Are you saying it
> is any random string that would generate an error?

It was delimited as "We should reject (that)" "that combination
(=cert+ferify-ca)" "the same way(=error-out)" "with cert+no-verify".

regards.

-- 
Kyotaro Horiguchi
NTT Open Source Software Center



pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: "cert" + clientcert=verify-ca in pg_hba.conf?
Next
From: Bruce Momjian
Date:
Subject: Re: "cert" + clientcert=verify-ca in pg_hba.conf?