Re: sslmode=require fallback - Mailing list pgsql-hackers

From Andrew Dunstan
Subject Re: sslmode=require fallback
Date
Msg-id 5789347C.5070304@dunslane.net
Whole thread Raw
In response to Re: sslmode=require fallback  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: sslmode=require fallback  (Peter Eisentraut <peter.eisentraut@2ndquadrant.com>)
List pgsql-hackers

On 07/15/2016 09:55 AM, Tom Lane wrote:

> I'm inclined to think that a better answer than changing libpq's behavior
> is to encourage DBAs to specify "hostssl" in pg_hba.conf for all external
> connections.    


Do those packagers who install dummy certificates and turn SSL on also 
change their pg_hba.conf.sample files to use hostssl?. That could go a 
long way towards encouraging people.

cheers

andrew




pgsql-hackers by date:

Previous
From: Матвеев Алексей
Date:
Subject: Re: One process per session lack of sharing
Next
From: Andres Freund
Date:
Subject: heap_xlog_lock forgets to reset HEAP_XMAX_INVALID