Re: DH_check return value test correct?

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Michael Fuhr <mike(at)fuhr(dot)org>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: DH_check return value test correct?
Date: 2006-05-12 22:39:44
Message-ID: 24012.1147473584@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Michael Fuhr <mike(at)fuhr(dot)org> writes:
> Isn't that the wrong test for DH_check's return value?

Yeah, sure looks that way, doesn't it?

> If $PGDATA/dh1024.pem exists and if SSL connections are enabled,
> then each SSL connection logs the following:
> DH_check error (dh1024.pem): No SSL error reported
> The backend then loads the hardcoded parameters. The SSL connection
> works, but with DH parameters other than intended.

So it's not that surprising that no one noticed it was broken :-(

regards, tom lane

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2006-05-12 22:52:12 Re: audit table containing Select statements submitted
Previous Message Albert Cervera Areny 2006-05-12 22:35:02 Re: Inheritance, Primary Keys and Foreign Keys