From:
Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To:
Peter Eisentraut <peter_e(at)gmx(dot)net>
Cc:
Bruce Momjian <bruce(at)momjian(dot)us>, pgsql-hackers(at)postgresql(dot)org
Subject:
Re: SSL over Unix-domain sockets
Date:
2008-01-05 17:39:08
Message-ID:
6866.1199554748@sss.pgh.pa.us (view raw or flat )
Thread:
2008-01-04 16:13:21 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-04 16:36:54 from Martijn van Oosterhout <kleptog(at)svana(dot)org>
2008-01-04 17:18:34 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-04 17:35:02 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-04 17:37:37 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-04 17:47:15 from Magnus Hagander <magnus(at)hagander(dot)net>
2008-01-04 17:57:28 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-04 18:36:52 from Aidan Van Dyk <aidan(at)highrise(dot)ca>
2008-01-04 19:09:59 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-04 19:37:03 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-04 20:08:07 from Andrew Sullivan <ajs(at)crankycanuck(dot)ca>
2008-01-05 13:13:46 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-05 17:39:08 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-05 19:14:53 from Mark Mielke <mark(at)mark(dot)mielke(dot)cc>
2008-01-05 21:05:20 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-14 22:20:54 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-15 03:24:06 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-15 03:33:28 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-15 04:14:29 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-15 04:35:30 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-15 12:21:21 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-15 13:54:46 from Aidan Van Dyk <aidan(at)highrise(dot)ca>
2008-01-15 14:54:51 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-15 12:05:45 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-15 15:46:32 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-15 15:55:02 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-15 16:28:11 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-15 20:14:56 from Greg Smith <gsmith(at)gregsmith(dot)com>
2008-01-17 13:44:12 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-15 16:58:20 from "Kevin Grittner" <Kevin(dot)Grittner(at)wicourts(dot)gov>
2008-01-15 14:23:53 from Martijn van Oosterhout <kleptog(at)svana(dot)org>
2008-01-15 16:06:41 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-17 02:58:11 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-17 08:10:52 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-17 16:10:47 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-17 16:31:40 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-17 16:35:58 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2008-01-18 00:47:26 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-18 01:37:23 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2008-01-18 01:50:40 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2008-01-18 02:16:42 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-18 08:37:00 from Greg Smith <gsmith(at)gregsmith(dot)com>
2008-01-18 02:17:33 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-18 02:21:18 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-18 02:21:19 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-01-18 02:24:26 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-31 17:32:46 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-01-18 02:42:05 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2008-01-18 10:38:23 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-18 10:24:09 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-18 10:59:49 from Magnus Hagander <magnus(at)hagander(dot)net>
2008-01-18 11:35:40 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-18 11:40:36 from Magnus Hagander <magnus(at)hagander(dot)net>
2008-01-18 10:22:41 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-15 09:10:37 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-01-15 09:25:21 from Magnus Hagander <magnus(at)hagander(dot)net>
Lists:
pgsql-hackers pgsql-patches
Peter Eisentraut <peter_e(at)gmx(dot)net> writes:
> Here is a patch that implements "localssl" as well. It is quite simple.
The other area that would need some thought before we could consider
this "done" is the behavior of libpq's sslmode parameter. With the
patch as given, an SSL-capable libpq will *default* to using SSL over
sockets, which might be thought overkill; it is almost certainly
going to result in a performance penalty. Is this a reasonable default
behavior? Should sslmode be extended to allow specification of
different behaviors for sockets vs. TCP?
regards, tom lane
In response to
Responses
pgsql-hackers by date
Next :From: Markus SchiltknechtDate: 2008-01-05 19:02:41
Subject : Re: Dynamic Partitioning using Segment Visibility Maps
Previous :From : Robert TreatDate : 2008-01-05 16:59:46
Subject : Re: Dynamic Partitioning using Segment Visibility Maps
pgsql-patches by date
Next :From: Mark MielkeDate: 2008-01-05 19:14:53
Subject : Re: SSL over Unix-domain sockets
Previous :From : Peter EisentrautDate : 2008-01-05 13:13:46
Subject : Re: SSL over Unix-domain sockets