Re: SSL SNI - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: SSL SNI
Date
Msg-id 5bf09acd-fcd8-052a-ae68-a51d7e02c458@enterprisedb.com
Whole thread Raw
In response to Re: SSL SNI  (Jesse Zhang <sbjesse@gmail.com>)
List pgsql-hackers
On 2021-02-15 18:40, Jesse Zhang wrote:
> I imagine this also (finally) opens up the possibility for the server
> to present a different certificate for each hostname based on SNI.
> This eliminates the requirement for wildcard certs where the cluster
> is running on a host with multiple (typically two to three) hostnames
> and the clients check the hostname against SAN in the cert
> (sslmode=verify-full). Am I right? Is that feature on anybody's
> roadmap?

This would be the client side of that.  But I don't know of anyone 
planning to work on the server side.



pgsql-hackers by date:

Previous
From: Anastasia Lubennikova
Date:
Subject: Re: CREATE INDEX CONCURRENTLY on partitioned index
Next
From: Justin Pryzby
Date:
Subject: Re: CREATE INDEX CONCURRENTLY on partitioned index