Re: openssl heartbleed - Mailing list pgsql-general

From Albe Laurenz
Subject Re: openssl heartbleed
Date
Msg-id A737B7A37273E048B164557ADEF4A58B17CEF450@ntex2010i.host.magwien.gv.at
Whole thread Raw
In response to Re: openssl heartbleed  (Steve Crawford <scrawford@pinpointresearch.com>)
Responses Re: openssl heartbleed  (John R Pierce <pierce@hogranch.com>)
Re: openssl heartbleed  (Steve Crawford <scrawford@pinpointresearch.com>)
List pgsql-general
Steve Crawford  wrote:
> On 04/09/2014 08:54 AM, "Gabriel E. Sánchez Martínez" wrote:
>> Hi all,
>>
>> Our server is running Ubuntu Server 13.10 (we will soon upgrade to
>> 14.04) and PostgreSQL 9.1.  We use certificates for all client
>> authentication on remote connections.  The server certificate is
>> self-signed.  In light of the heartbleed bug, should we create a new
>> server certificate and replace all client certificates?  My guess is yes.

[...]

> If you aren't and weren't running a vulnerable version or if the
> vulnerable systems were entirely within a trusted network space with no
> direct external access then you are probably at low to no risk and need
> to evaluate the cost of updates against the low level of risk.

If you are in a totally trusted environment, why would you use SSL?

Yours,
Laurenz Albe

pgsql-general by date:

Previous
From: Stuart Bishop
Date:
Subject: Re: Linux vs FreeBSD
Next
From: John R Pierce
Date:
Subject: Re: openssl heartbleed