[GENERAL] Configuring ssl_crl_file - Mailing list pgsql-general

From Frazer McLean
Subject [GENERAL] Configuring ssl_crl_file
Date
Msg-id C5157FCB-26C3-42E8-8C71-17B83416E89D@frazermclean.co.uk
Whole thread Raw
Responses Re: [GENERAL] Configuring ssl_crl_file  ("Frazer McLean" <frazer@frazermclean.co.uk>)
List pgsql-general
Hi,

I was trying to set up PostgreSQL to use a certificate revocation list
so I could revoke client certificates, but was unable to get it to work.

I was following [this tutorial][1] to create root and intermediate CA
certificates, then producing certificates for the PostgreSQL server and
client.

I have created a [Dockerfile][2] which shows the problem. The short
story is that with the CRL I’ve created in PEM format, a client
certificate is rejected with error “psql: SSL error: tlsv1 alert
unknown ca”. If I don’t set ssl_crl_file, the client certificate is
accepted.

I tested on 9.4-9.6. I tried to find examples about using ssl_crl_file
but wasn’t able to find anything. I found [this message][3] from 2014
without any replies.

[1]:
https://jamielinux.com/docs/openssl-certificate-authority/index.html
[2]: https://github.com/RazerM/postgres_crl_test
[3]: https://postgrespro.com/list/thread-id/1163456

Kind regards,

Frazer McLean


pgsql-general by date:

Previous
From: Rich Shepard
Date:
Subject: Re: [GENERAL] New 9.6.2 installation lacks /usr/lib/postgresql/[RESOLVED]
Next
From: Geoff Winkless
Date:
Subject: Re: [GENERAL] ERROR: functions in index expression must be marked IMMUTABLE