Re: pg_stat_ssl additions - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: pg_stat_ssl additions
Date
Msg-id d80f6c25-643f-a9b8-787e-3b05e2c13911@2ndquadrant.com
Whole thread Raw
In response to Re: pg_stat_ssl additions  (Lou Picciano <LouPicciano@comcast.net>)
Responses Re: pg_stat_ssl additions  (Peter Eisentraut <peter.eisentraut@2ndquadrant.com>)
List pgsql-hackers
On 29/11/2018 01:27, Lou Picciano wrote:
> Further, I’m not sure exposing details about Cert Issuer, etc. to
> non-privileged users is much of an issue. For the most part, in most use
> cases, ‘users’ should//would/ want to know what entity is the issuer. If
> we’re talking about client certs, most of this is readily readable
> anyway, no?

The debate is whether an unprivileged user should be able to read the
SSL information of *other* users' connections.

My opinion is no.

-- 
Peter Eisentraut              http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services


pgsql-hackers by date:

Previous
From: Dmitry Dolgov
Date:
Subject: Re: [HACKERS] proposal - Default namespaces for XPath expressions(PostgreSQL 11)
Next
From: Dmitry Dolgov
Date:
Subject: Re: [HACKERS] SERIALIZABLE on standby servers