Re: Relaxing SSL key permission checks - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: Relaxing SSL key permission checks
Date
Msg-id 56E22B60.9010108@gmx.net
Whole thread Raw
In response to Re: Relaxing SSL key permission checks  (Alvaro Herrera <alvherre@2ndquadrant.com>)
Responses Re: Relaxing SSL key permission checks
List pgsql-hackers
On 3/4/16 3:55 PM, Alvaro Herrera wrote:
> * it failed to check for S_IXUSR, so permissions 0700 were okay, in
> contradiction with what the error message indicates.  This is a
> preexisting bug actually.  Do we want to fix it by preventing a
> user-executable file (possibly breaking compability with existing
> executable key files), or do we want to document what the restriction
> really is?

I think we should not check for S_IXUSR.  There is no reason for doing that.

I can imagine that key files are sometimes copied around using USB
drives with FAT file systems or other means of that sort where
permissions can scrambled.  While I hate gratuitous executable bits as
much as the next person, insisting here would just create annoyances in
practice.




pgsql-hackers by date:

Previous
From: Peter Eisentraut
Date:
Subject: Re: Fix for OpenSSL error queue bug
Next
From: Robert Haas
Date:
Subject: Re: [COMMITTERS] pgsql: Provide much better wait information in pg_stat_activity.