Re: Upcoming re-releases - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Upcoming re-releases
Date
Msg-id 8731.1139678170@sss.pgh.pa.us
Whole thread Raw
In response to Re: Upcoming re-releases  ("Magnus Hagander" <mha@sollentuna.net>)
List pgsql-hackers
"Magnus Hagander" <mha@sollentuna.net> writes:
> If you stick a root certificate (root.crt in ~/.postgresql) for it to
> validate against, it will be validated against that root. I'm not sure
> if it validates the common name of the cert though - that would be an
> issue if you're using a global CA. If you're using a local enterprise
> CA, that's a much smaller issue (because you yourself have total control
> over who gets certificates issued by the CA).

But in either case, it would only be checking that the cert had been
issued by that CA, no?  Unless you set up a CA that only ever issues
certificates to your PG server, someone else with a cert from the CA
could still impersonate.  Or am I mistaken about that?
        regards, tom lane


pgsql-hackers by date:

Previous
From: "Magnus Hagander"
Date:
Subject: Re: Upcoming re-releases
Next
From: Greg Stark
Date:
Subject: Re: PostgreSQL 8.0.6 crash