From: | Christoph Berg <myon(at)debian(dot)org> |
---|---|
To: | Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com> |
Cc: | Andrew Dunstan <andrew(at)dunslane(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, Robert Haas <robertmhaas(at)gmail(dot)com>, Jakob Egger <jakob(at)eggerapps(dot)at>, PostgreSQL Hackers <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: sslmode=require fallback |
Date: | 2016-07-17 20:07:00 |
Message-ID: | 20160717200700.xee3ksttbhkp2e4h@msg.df7cb.de |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
Re: Peter Eisentraut 2016-07-17 <d6b22200-0e65-d17e-b227-b63d81720fd0(at)2ndquadrant(dot)com>
> On 7/15/16 3:07 PM, Andrew Dunstan wrote:
> > Do those packagers who install dummy certificates and turn SSL on also
> > change their pg_hba.conf.sample files to use hostssl?. That could go a
> > long way towards encouraging people.
>
> Debian, which I guess sort of started this, does not, but there are
> allusions to it in the TODO list.
I guess we should actually do that if we had any non-local(host)
entries in there by default, but we don't touch the default
pg_hba.conf from pg_createcluster.
Possibly we could add some hostssl example in comments to the end of
the .sample file so people could grow the habit of using that instead
of host (I certainly aren't doing myself that yet), but I'd rather see
that changed upstream.
So, how about something like this for the end of pg_hba.conf.sample?
# Examples for allowing access from given networks:
#hostssl all all 192.0.2.0/24 @authmethod@
#hostssl all all 2001:DB8::/32 @authmethod@
(These are "documentation" networks from RF5737/RFC3849.)
Christoph
From | Date | Subject | |
---|---|---|---|
Next Message | Joshua D. Drake | 2016-07-17 21:16:41 | Re: A Modest Upgrade Proposal |
Previous Message | Petr Jelinek | 2016-07-17 20:02:26 | Re: A Modest Upgrade Proposal |