| From: | Rui Zhao <zhaorui126(at)gmail(dot)com> |
|---|---|
| To: | Daniel Gustafsson <daniel(at)yesql(dot)se> |
| Cc: | Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com>, Zsolt Parragi <zsolt(dot)parragi(at)percona(dot)com>, Pgsql Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, Noah Misch <noah(at)leadboat(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
| Subject: | Re: Serverside SNI support in libpq |
| Date: | 2026-10-04 15:50:44 |
| Message-ID: | CAHWVJhFSDVQbujefKnQNA2yB27aKgxZDU+BVQNYy7U6crGhCjQ@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
Hi Daniel,
Thanks very much for fixing these SSL reload and cleanup issues. I also
ran into the SNI reload issue while reviewing the DH parameter patch
and wrote a patch to try to fix it. I then checked whether the same
problem had already been reported, which led me to this thread.
I've reviewed all five patches in v5. They look good to me, and I
didn't find any further problems. The attached patch adds tests on top
of v5 for a few cases missing from 004_sni.pl:
1. Enabling SNI by reloading with an encrypted per-host key and its own
passphrase command. The existing encrypted-key tests start with SNI
already enabled.
2. Turning SNI off while ssl_cert_file points to a missing file, with a
default host configured. The default and named hosts use different
certificates, so verify-full checks that the failed reload leaves
the named host's certificate in use.
3. Retrying the reload after restoring a valid global certificate and
key. The test checks that SNI host selection is disabled and a new
connection verifies the global certificate.
The added tests pass with v5.
Regards,
Rui
| Attachment | Content-Type | Size |
|---|---|---|
| nocfbot-0001-Test-SNI-certificate-selection-across-configuration-reloads.patch | application/octet-stream | 4.4 KB |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Alexandre Felipe | 2026-10-04 16:06:20 | Re: Throwing away unnecessary spin-locks |
| Previous Message | Peter Eisentraut | 2026-10-04 14:59:02 | Re: Silence -fsanitize=function where we cast function pointers on purpose |