Re: libpq 8.4 beta1: $PGHOST complains about missing root.crt

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Peter Eisentraut <peter_e(at)gmx(dot)net>
Cc: pgsql-bugs(at)postgresql(dot)org, Martin Pitt <mpitt(at)debian(dot)org>
Subject: Re: libpq 8.4 beta1: $PGHOST complains about missing root.crt
Date: 2009-04-11 01:42:59
Message-ID: 20090411014259.GI8123@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

* Peter Eisentraut (peter_e(at)gmx(dot)net) wrote:
> The new firefox just says "invalid certificate" and nothing else, and then
> somewhere below there is a small link to "Add an exception" and you need a
> total of four clicks to proceed. So that looks a lot like that they are
> moving away from easily allowing unverifyable server certificates as well.

Yes, it's extremely obnoxious and hasn't actually changed anything. We
often use certificates at work for internal web sites that aren't signed
by the santified CAs simply because it's not worth it. That causes
problems for our users when they're going to sites that are about a
billion times less likely to have been cracked into than Joe's crab shop
out on the internet. Encouraging people to believe that the PKI that's
currently being used for the web is actually meaningful is really the
first mistake.

Stephen

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message John R Pierce 2009-04-11 03:34:02 Re: libpq 8.4 beta1: $PGHOST complains about missing root.crt
Previous Message Stephen Frost 2009-04-11 01:39:46 Re: libpq 8.4 beta1: $PGHOST complains about missing root.crt