Re: Changing client-side behavior regarding Certificate Revocation Lists (CRL)

From: Daniel Gustafsson <daniel(at)yesql(dot)se>
To: Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com>
Cc: Михаил Купцов <mr(dot)cuptsov2018(at)yandex(dot)ru>, "pgsql-hackers(at)lists(dot)postgresql(dot)org" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: Changing client-side behavior regarding Certificate Revocation Lists (CRL)
Date: 2026-08-25 21:36:07
Message-ID: 75264BFF-34C4-44A5-ACA8-1DB7D0B6582D@yesql.se
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

> On 25 Aug 2026, at 17:24, Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com> wrote:
> On Tue, Aug 25, 2026 at 1:08 AM Daniel Gustafsson <daniel(at)yesql(dot)se> wrote:

>> I think a stricter CRL policy would need another trigger.
>
> More fuel for the fire of a .libpqrc, maybe?

That could certainly be a trigger. I was also thinking around how we have a
set of sslmodes which cover the usecases of yesteryear with less options for
todays world of security hardening, but .libpqrc is likely a better fit here.

--
Daniel Gustafsson

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Heikki Linnakangas 2026-08-25 21:39:55 Re: RegisterShmemCallbacks() does nothing in single-user mode
Previous Message Jesper Pedersen 2026-08-25 20:36:25 Re: scary patch contest