Re: using ssl some of the time

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
Cc: Charles Hornberger <charlie(at)hss(dot)caltech(dot)edu>, pgsql-admin(at)postgresql(dot)org
Subject: Re: using ssl some of the time
Date: 2003-07-24 21:29:03
Message-ID: 20729.1059082143@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

> Charles Hornberger wrote:
>> Just a quick follow-up to share one (!) data point, which looks to me
>> like it indicates that SSL encryption/decryption is pretty expensive on
>> one of our Sun Ultra 5 boxes. The following query ("select * from wp")
>> generates ~270K of output. When executed via a psql client that's
>> connected over a non-encrypted link, it takes 0.7 seconds; over an
>> encrypted link, it takes more than 10 times that long.

I suspect most of this is from the ridiculously small renegotiation
interval we put into 7.3. Try increasing RENEGOTIATION_LIMIT in
src/backend/libpq/be-secure.c (we've bumped it to 512 meg for 7.4).

regards, tom lane

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Bruce Momjian 2003-07-24 21:53:04 Re: using ssl some of the time
Previous Message Bruce Momjian 2003-07-24 20:44:48 Re: using ssl some of the time