Re: re-reading SSL certificates during server reload - Mailing list pgsql-hackers

From Magnus Hagander
Subject Re: re-reading SSL certificates during server reload
Date
Msg-id CABUevEzpZx534tjH==92truM01A=ZwD60Jk7+BnU2_V--U3sOQ@mail.gmail.com
Whole thread Raw
In response to Re: re-reading SSL certificates during server reload  (Andres Freund <andres@2ndquadrant.com>)
List pgsql-hackers
On Thu, Aug 28, 2014 at 4:14 PM, Andres Freund <andres@2ndquadrant.com> wrote:
> On 2014-08-28 10:12:19 -0400, Tom Lane wrote:
>> Magnus Hagander <magnus@hagander.net> writes:
>> > On Thu, Aug 28, 2014 at 4:05 PM, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>> >> Why would they need to be BACKEND, as opposed to just PGC_SIGHUP?
>>
>> > I just thought semantically - because they do not change in a running
>> > backend. Any running backend will continue with encryption set up
>> > based on the old certificate.
>>
>> Hm.  Yeah, I guess there is some use in holding onto the values that were
>> actually used to initialize the current session, or at least there would
>> be if we exposed the cert contents in any fashion.
>
> Won't that allow the option to be specified at connection start by mere
> mortal users? That sounds odd to me.

The cert is (and has to be) loaded before we even read the startup
packet, so there is no way for them to actually send the value over
early enough I believe.


-- Magnus HaganderMe: http://www.hagander.net/Work: http://www.redpill-linpro.com/



pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: re-reading SSL certificates during server reload
Next
From: Amit Kapila
Date:
Subject: Re: Audit of logout