Re: SSL cleanups/hostname verification - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: SSL cleanups/hostname verification
Date
Msg-id 48FD8C83.9000805@gmx.net
Whole thread Raw
In response to Re: SSL cleanups/hostname verification  ("Robert Haas" <robertmhaas@gmail.com>)
Responses Re: SSL cleanups/hostname verification
List pgsql-hackers
Robert Haas wrote:
>>> How can you make that the default?  Won't it immediately break every
>>> installation without certificates?
>> *all* SSL installations have certificate on the server side. You cannot
>> run without it.
> 
> s/without certificates/with self-signed certificates/
> 
> which I would guess to be a common configuration

Yeah, but those setups are already broken anyway; the users just appear 
not to know it.

If you install a new web browser, would you want it to be configured by 
default to warn about untrusted certificates or to "not bother" the user 
about it?  It's pretty much the same question here.


pgsql-hackers by date:

Previous
From: Zeugswetter Andreas OSB sIT
Date:
Subject: Re: Hot Standby utility and administrator functions
Next
From: Peter Eisentraut
Date:
Subject: Re: SSL cleanups/hostname verification