Re: [JDBC] [HACKERS] Channel binding support for SCRAM-SHA-256

From: Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>
To: Michael Paquier <michael(dot)paquier(at)gmail(dot)com>
Cc: Robert Haas <robertmhaas(at)gmail(dot)com>, Álvaro Hernández Tortosa <aht(at)8kdata(dot)com>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: [JDBC] [HACKERS] Channel binding support for SCRAM-SHA-256
Date: 2018-01-04 20:41:39
Message-ID: 9ac07df0-784a-cb03-a9e1-1454eca16b3b@2ndquadrant.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-jdbc

On 12/28/17 02:19, Michael Paquier wrote:
> On Wed, Dec 27, 2017 at 09:27:40AM +0900, Michael Paquier wrote:
>> On Tue, Dec 26, 2017 at 03:28:09PM -0500, Peter Eisentraut wrote:
>>> On 12/22/17 03:10, Michael Paquier wrote:
>>>> Second thoughts on 0002 as there is actually no need to move around
>>>> errorMessage if the PGconn* pointer is saved in the SCRAM status data
>>>> as both are linked. The attached simplifies the logic even more.
>>>>
>>>
>>> That all looks pretty reasonable.
>>
>> Thanks for the review. Don't you think that the the refactoring
>> simplifications should be done first though? This would result in
>> producing the patch set in reverse order. I'll be fine to produce them
>> if need be.
>
> Well, here is a patch set doing the reverse operation: refactoring does
> first in 0001 and support for tls-server-end-point is in 0002. Hope this
> helps.

committed

I reorganized the be_tls_get_certificate_hash() and
pgtls_get_peer_certificate_hash() functions a bit to not have most of
the code in a big if statement.

--
Peter Eisentraut http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Andres Freund 2018-01-04 20:47:41 Re: pgsql: Add parallel-aware hash joins.
Previous Message Andrew Dunstan 2018-01-04 20:39:41 Re: Announcing Release 6 of PostgreSQL Buildfarm client

Browse pgsql-jdbc by date

  From Date Subject
Next Message Peter Eisentraut 2018-01-04 20:56:32 Re: [JDBC] [HACKERS] Channel binding support for SCRAM-SHA-256
Previous Message Chen Huajun 2018-01-03 17:04:20 [pgjdbc/pgjdbc] c6fec3: fix: improve multihost connection for preferSlave ...