"Web of trust" connections - Mailing list pgsql-general

From Mark Morgan Lloyd
Subject "Web of trust" connections
Date
Msg-id n1ibrv$ejk$1@pye-srv-01.telemetry.co.uk
Whole thread Raw
Responses Re: "Web of trust" connections  (Jim Nasby <Jim.Nasby@BlueTreble.com>)
List pgsql-general
Purely out of curiosity, is there any way of using some sort of "web of
trust" (comparable with GPG or whatever) when verifying server and
client certificates, rather than going back to a centralised CA?

My apologies if this is a silly question, or if there are fundamental
reasons why such a thing would be inappropriate. My scenario is that I'm
looking at multiple PostgreSQL servers (with supporting custom software)
arranged (approximately) as a tree, with nodes sending notifications to
their peers as they see changes. I want to make it as easy as possible
to set up a new server and get it cooperating with the rest, and some
sort of WoT might be plausible rather than having to wait for the root
administrator to send keys over a secure channel.

--
Mark Morgan Lloyd
markMLl .AT. telemetry.co .DOT. uk

[Opinions above are the author's, not those of his employers or colleagues]


pgsql-general by date:

Previous
From: Albe Laurenz
Date:
Subject: Re: pg_archivecleanup not deleting anything?
Next
From: Tom Lane
Date:
Subject: Re: is there any difference DROP PRIMARY KEY in oracle and postgres?