Re: OpenSSL Applink - Mailing list pgsql-patches

From Magnus Hagander
Subject Re: OpenSSL Applink
Date
Msg-id 46FD6D5E.7010501@hagander.net
Whole thread Raw
In response to Re: OpenSSL Applink  (Dave Page <dpage@postgresql.org>)
Responses Re: OpenSSL Applink  (Dave Page <dpage@postgresql.org>)
List pgsql-patches
Dave Page wrote:
> Magnus Hagander wrote:
>> Dave Page wrote:
>>> Dave Page wrote:
>>>> Dave Page wrote:
>>>>> I did stumble across this text on a mailing list in response to someone
>>>>> with a similar problem in some JNI code. I know little of the OpenSSL
>>>>> API, but perhaps it rings bells with you before I spend my evening
>>>>> trying to figure it out?
>>>> OK, I think I've figured out a fix. Working up a patch now...
>>> Patch attached.
>> (sorry, been offline for the day)
>>
>> Is there any reason not to just do this on *all* platforms, and get rid
>> of all the #ifdefs?
>
> Yes, (see the comment in the code). We stat the private key on *nix to
> ensure it hasn't changed underneath us which can't be done using the BIO
> functions... though I wonder if we can get the FILE pointer from BIO and
> do it that way. Should be as safe on *nix as what we currently do.

Hrrm. Obviously, I need to go sleep now. Sorry about that.

But it'd be nice to get rid of all those #ifdef blocks..

//Magnus

pgsql-patches by date:

Previous
From: Bruce Momjian
Date:
Subject: TCL fix in HEAD
Next
From: Dave Page
Date:
Subject: Re: OpenSSL Applink