pgsql/src backend/libpq/be-secure.c interfaces ...

From: momjian(at)postgresql(dot)org (Bruce Momjian - CVS)
To: pgsql-committers(at)postgresql(dot)org
Subject: pgsql/src backend/libpq/be-secure.c interfaces ...
Date: 2002-06-14 04:31:49
Message-ID: 20020614043149.90921477289@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers

CVSROOT: /cvsroot
Module name: pgsql
Changes by: momjian(at)postgresql(dot)org 02/06/14 00:31:49

Modified files:
src/backend/libpq: be-secure.c
src/interfaces/libpq: fe-secure.c

Log message:
SSL support for ephemeral DH keys.

As the comment headers in be-secure.c discusses, EPH preserves
confidentiality even if the static private key (which is usually
kept unencrypted) is compromised.

Because of the value of this, common default values are hard-coded
to protect the confidentiality of the data even if an attacker
successfully deletes or modifies the external file.

Bear Giles

Browse pgsql-committers by date

  From Date Subject
Next Message Bruce Momjian - CVS 2002-06-14 04:33:53 pgsql/src backend/libpq/be-secure.c include/li ...
Previous Message Bruce Momjian - CVS 2002-06-14 04:23:17 pgsql/src backend/libpq/Makefile backend/libpq ...