Re: ssl passphrase callback - Mailing list pgsql-hackers

From Simon Riggs
Subject Re: ssl passphrase callback
Date
Msg-id CANP8+jKGDEmSmjZwwjqqMsWSLRqTVc5qLwk_xMvR7PH9jNLiBw@mail.gmail.com
Whole thread Raw
In response to Re: ssl passphrase callback  (Bruce Momjian <bruce@momjian.us>)
Responses Re: ssl passphrase callback
List pgsql-hackers
On Thu, 7 Nov 2019 at 10:24, Bruce Momjian <bruce@momjian.us> wrote:
 
What is the value of a shared library over a shell command?  We had this
discussion in relation to archive_command years ago, and decided on a
shell command as the best API.

I don't recall such a discussion, but I can give perspective:

* shell command offered the widest and simplest API for integration, which was the most important consideration for a backup API. That choice caused difficulty with the need to pass information to the external command, e.g. %f %p

* shared library is more appropriate for a security-related module, so users can't see how it is configured, as well as being more tightly integrated so it can be better tailored to various uses

Summary is that the choice is not random, nor mere preference

--
Simon Riggs                http://www.2ndQuadrant.com/
PostgreSQL Solutions for the Enterprise

pgsql-hackers by date:

Previous
From: Julien Rouhaud
Date:
Subject: Re: Monitoring disk space from within the server
Next
From: Joe Conway
Date:
Subject: Re: add a MAC check for TRUNCATE