Re: pg_hba.conf

From: "Nigel J(dot) Andrews" <nandrews(at)investsystems(dot)co(dot)uk>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Angel Todorov <atodorov(at)acm(dot)org>, pgsql-general(at)postgresql(dot)org
Subject: Re: pg_hba.conf
Date: 2003-09-30 17:39:53
Message-ID: Pine.LNX.4.21.0309301833510.14571-100000@ponder.fairway2k.co.uk
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Tue, 30 Sep 2003, Tom Lane wrote:

> "Nigel J. Andrews" <nandrews(at)investsystems(dot)co(dot)uk> writes:
> > In 7.3 and less ssl connections fail if a host line matches before the hostssl
> > line. At least I think that's the situation, there is definitely something
> > there that will make a ssl connection get rejected even if there is an
> > appropiate entry in pg_hba.conf
>
> Really? Can you show an example?

Well, not at the moment. I'd have to remember the specifics as well. I think it
was something to do with the client being built with ssl but the server not. Or
it might have been both built with ssl and a host line appearing before hostssl
in pg_hba.conf.

Whatever, I believe this was addressed by someone, possibly with the
introduction of a GUC.

I'll have to see if I can scrape the time together to try things out again but
I'm very busy, what with people struggling to make something work on production
when it was working on dev only to eventually say what the problem actually is
so it could be solved in a couple of seconds.

--
Nigel J. Andrews

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Stephan Szabo 2003-09-30 18:10:30 Re: ADD FOREIGN KEY (was Re: [GENERAL] 7.4Beta)
Previous Message Jan Wieck 2003-09-30 17:28:04 Re: ADD FOREIGN KEY (was Re: [GENERAL] 7.4Beta)