Re: BUG #4340: SECURITY: Is SSL Doing Anything?

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Dan Kaminsky <dan(at)doxpara(dot)com>
Cc: pgsql-bugs(at)postgresql(dot)org
Subject: Re: BUG #4340: SECURITY: Is SSL Doing Anything?
Date: 2008-08-04 16:24:30
Message-ID: 5845.1217867070@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

Dan Kaminsky <dan(at)doxpara(dot)com> writes:
> Lets talk about the verify_cb callback first: Suppose there's a
> man-in-the-middle between the PG client and the PG server. Is some
> secondary force going to apply some Trusted CA list?

I'm not sure why we have verify_cb at all -- so far as I can see,
it just specifies the same behavior as OpenSSL's default. Are
you saying that OpenSSL's default verification behavior is broken?

> Second, are you saying verify_peer doesn't do anything for
> authentication? Are you sure about that? There's really little reason
> otherwise for the call to exist.

Er, we don't *have* a verify_peer callback.

regards, tom lane

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Markus Wanner 2008-08-05 12:20:57 Re: BUG #4339: The postgreSQL service stops abnormally
Previous Message Dan Kaminsky 2008-08-04 16:05:37 Re: BUG #4340: SECURITY: Is SSL Doing Anything?