Re: host and hostssl equivalence in pg_hba.conf - Mailing list pgsql-hackers

From Tom Lane
Subject Re: host and hostssl equivalence in pg_hba.conf
Date
Msg-id 2451.1055254260@sss.pgh.pa.us
Whole thread Raw
In response to Re: host and hostssl equivalence in pg_hba.conf  ("Nigel J. Andrews" <nandrews@investsystems.co.uk>)
List pgsql-hackers
"Nigel J. Andrews" <nandrews@investsystems.co.uk> writes:
> On Tue, 10 Jun 2003, Tom Lane wrote:
>> If your real gripe is that libpq insists on trying SSL connections
>> first, the server is the wrong end to be patching that problem at.
>> There should be a way to control libpq's allow_ssl_try state variable
>> from the outside.

> A quick read makes me think that's what Jon's post is on about.

Right.  I had forgotten that thread, but indeed we had agreed to a
definition that would allow flexible control of libpq's SSL behavior.
Looks like no one got round to actually implementing what was hammered
out though.

Note: if you want to take a swipe at implementing that proposal, please
be sure to start from CVS tip.  I mangled all that code just a couple
days ago to allow both old and new protocols to be supported ... so any
patch based on 7.3 is not going to apply ...
        regards, tom lane


pgsql-hackers by date:

Previous
From: "Nigel J. Andrews"
Date:
Subject: Re: host and hostssl equivalence in pg_hba.conf
Next
From: "scott.marlowe"
Date:
Subject: Re: security flaw