Re: pg_hba.conf.sample wording improvement - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: pg_hba.conf.sample wording improvement
Date
Msg-id cec26985-cdff-1590-8343-b8b06a192b8f@enterprisedb.com
Whole thread Raw
In response to Re: pg_hba.conf.sample wording improvement  (Alvaro Herrera <alvherre@alvh.no-ip.org>)
Responses Re: pg_hba.conf.sample wording improvement  (Magnus Hagander <magnus@hagander.net>)
List pgsql-hackers
On 28.04.21 16:09, Alvaro Herrera wrote:
> Looking at it now, I wonder how well do the "hostno" options work.  If I
> say "hostnogssenc", is an SSL-encrypted socket good?  If I say
> "hostnossl", is a GSS-encrypted socket good?  If so, how does that make
> sense?

I think for example if you want to enforce SSL connections, then writing 
"hostnossl ... reject" would be sensible.  That would also reject 
GSS-encrypted connections, but that would be what you want in that scenario.




pgsql-hackers by date:

Previous
From: Amit Kapila
Date:
Subject: Re: Replication slot stats misgivings
Next
From: Amit Kapila
Date:
Subject: Re: Unresolved repliaction hang and stop problem.