Re: Support for NSS as a libpq TLS backend - Mailing list pgsql-hackers

From Jacob Champion
Subject Re: Support for NSS as a libpq TLS backend
Date
Msg-id 78ae2dcf73f64b95a62813ebe5a8f4e1ce681b7f.camel@vmware.com
Whole thread Raw
In response to Re: Support for NSS as a libpq TLS backend  (Daniel Gustafsson <daniel@yesql.se>)
List pgsql-hackers
On Wed, 2021-02-17 at 22:19 +0100, Daniel Gustafsson wrote:
> > On 17 Feb 2021, at 02:02, Jacob Champion <pchampion@vmware.com> wrote:
> > Would that be desirable, or do we want this interface to be something
> > more generally compatible with (some as-of-yet unspecified) spec?
> 
> Regardless of approach taken I think this sounds like something that should be
> tackled in a follow-up patch if the NSS patch is merged - and probably only as
> a follow-up to a patch that adds test coverage to sslinfo.

Sounds good, and +1 to adding coverage at the same time.

> From the sounds of
> things me may not be able to guarantee stability across OpenSSL versions as it
> is right now?

Yeah. I was going to write that OpenSSL would be unlikely to change
these once they're added for the first time, but after checking GitHub
it looks like they have done so recently [1], as part of a patch
release no less.

--Jacob

[1] https://github.com/openssl/openssl/pull/10029

pgsql-hackers by date:

Previous
From: Thomas Munro
Date:
Subject: Re: pg_collation_actual_version() ERROR: cache lookup failed for collation 123
Next
From: Robert Haas
Date:
Subject: Re: new heapcheck contrib module