SSL Client Authentication - Mailing list pgsql-general

From Tim Tassonis
Subject SSL Client Authentication
Date
Msg-id 443A438A.6090707@cubic.ch
Whole thread Raw
List pgsql-general
Hi List

I'm currently playing with SSL support in PostgreSQL and have a few
questions:


SSL in general seems to work fine, but the client does not seem to
perform any server verification (Hostname or CA). Is suport for this
planned?

Client Authentication seems to work as well, but there seems to be no
mapping done from the Client Cert to a database. So there seems to very
little use of enabling client authentication.

Do plans exist with regard to enhance SSL/TLS support in PostgreSQL?

I think the following would be nice:

- Server Verification possible.
- Passwordless Client Authentication with Userid mapping to Cert DN

Oracle for instance does this like this:


alter user jdoe identified externally as 'cn=jdoe,....'

MySQL does it like this:

grant priv on db1.* to jdoe@'%' REQUIRE SUBJECT '/../CN=jdoe';


Bye
Tim



pgsql-general by date:

Previous
From: Martijn van Oosterhout
Date:
Subject: Re: Debian package for freeradius_postgresql module
Next
From: "Holger Hoffstaette"
Date:
Subject: Re: Postgres Library natively available for Mac OSX Intel?