Magnus Hagander <magnus@hagander.net> writes:
> I noticed while working on general fixes for the certificate handling
> that if we have a connection being attempted with sslmode=prefer (which
> happens to be our default), we will loose error messages.
Yeah, this came up awhile ago. I don't see any easy solution that
isn't just moving the bad cases around ... although maybe moving them
away from the default/common cases could be a good thing anyway.
> Basically, if we fail the SSL connection, we will throw away the error
> message and try a cleartext connection.
Maybe the answer is to not throw away the first error message? But
presenting both messages could be confusing too.
regards, tom lane