Re: SSL cleanups/hostname verification - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: SSL cleanups/hostname verification
Date
Msg-id 48FD8CF2.8040803@gmx.net
Whole thread Raw
In response to Re: SSL cleanups/hostname verification  (Magnus Hagander <magnus@hagander.net>)
Responses Re: SSL cleanups/hostname verification
Re: SSL cleanups/hostname verification
List pgsql-hackers
Magnus Hagander wrote:
> Robert Haas wrote:
>>>> How can you make that the default?  Won't it immediately break every
>>>> installation without certificates?
>>> *all* SSL installations have certificate on the server side. You cannot
>>> run without it.
>> s/without certificates/with self-signed certificates/
>>
>> which I would guess to be a common configuration
> 
> Self-signed still work. In a self-signed scenario, the server
> certificate *is* the CA certificate.

But the user needs to copy the CA to the client, which most people 
probably don't do nowadays.


pgsql-hackers by date:

Previous
From: Peter Eisentraut
Date:
Subject: Re: SSL cleanups/hostname verification
Next
From: Magnus Hagander
Date:
Subject: Re: SSL cleanups/hostname verification