Re: libpq ssl -> clear fallback looses error messages - Mailing list pgsql-hackers

From Magnus Hagander
Subject Re: libpq ssl -> clear fallback looses error messages
Date
Msg-id 48EFE8C1.1050004@hagander.net
Whole thread Raw
In response to Re: libpq ssl -> clear fallback looses error messages  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: libpq ssl -> clear fallback looses error messages  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Tom Lane wrote:
> Magnus Hagander <magnus@hagander.net> writes:
>> I noticed while working on general fixes for the certificate handling
>> that if we have a connection being attempted with sslmode=prefer (which
>> happens to be our default), we will loose error messages.
> 
> Yeah, this came up awhile ago.  I don't see any easy solution that
> isn't just moving the bad cases around ... although maybe moving them
> away from the default/common cases could be a good thing anyway.

I think it would.

>> Basically, if we fail the SSL connection, we will throw away the error
>> message and try a cleartext connection.
> 
> Maybe the answer is to not throw away the first error message?  But
> presenting both messages could be confusing too.

Do we have the infrastructure to report more than one error? I thought
we didn't...

//Magnus


pgsql-hackers by date:

Previous
From: Josh Berkus
Date:
Subject: The Axe list
Next
From: Tom Lane
Date:
Subject: Re: Contrib, schema, and load_module