Re: [PATCH] add ssl_protocols configuration option - Mailing list pgsql-hackers

From Alex Shulgin
Subject Re: [PATCH] add ssl_protocols configuration option
Date
Msg-id 87mw7daj5t.fsf@commandprompt.com
Whole thread Raw
In response to Re: [PATCH] add ssl_protocols configuration option  (Alex Shulgin <ash@commandprompt.com>)
Responses Re: [PATCH] add ssl_protocols configuration option  (Dag-Erling Smørgrav <des@des.no>)
List pgsql-hackers
Alex Shulgin <ash@commandprompt.com> writes:
>>>
>>> I can do that too, just need a hint where to look at in libpq/psql to
>>> add the option.
>>
>> The place to *enforce* the option is src/interfaces/libpq/fe-secure.c
>> (look for SSLv23_method() and SSL_CTX_set_options()).  I haven't looked
>> into how to set it.
>
> Yes, I've figured it out.  Guess we'd better share the ssl_protocol
> value parser code between libpq and the backend.  Any precedent?

OK, looks like I've come up with something workable: I've added
sslprotocol connection string keyword similar to pre-existing
sslcompression, etc.

Please see attached v2 of the original patch.  I'm having doubts about
the name of openssl.h header though, libpq-openssl.h?

--
Alex


Attachment

pgsql-hackers by date:

Previous
From: Alvaro Herrera
Date:
Subject: Re: no test programs in contrib
Next
From: Pavel Stehule
Date:
Subject: Re: proposal: plpgsql - Assert statement