Re: Should we back-patch SSL renegotiation fixes?

From: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
To: Peter Eisentraut <peter_e(at)gmx(dot)net>, Andres Freund <andres(at)anarazel(dot)de>, Robert Haas <robertmhaas(at)gmail(dot)com>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Should we back-patch SSL renegotiation fixes?
Date: 2015-06-25 17:06:10
Message-ID: 558C3502.9020301@commandprompt.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers


On 06/25/2015 06:15 AM, Peter Eisentraut wrote:
>
> On 6/25/15 8:03 AM, Andres Freund wrote:
>> Right now if you use streaming rep over ssl, it breaks after a couple
>> hundred megabytes with obscure errors.
>
> If it's that bad, then I tend to agree we should turn it off by default.
>

From an "in the wild perspective", we run into this all the time.

+1 to turn it off by default in all supported branches.

JD

--
Command Prompt, Inc. - http://www.commandprompt.com/ 503-667-4564
PostgreSQL Centered full stack support, consulting and development.
Announcing "I'm offended" is basically telling the world you can't
control your own emotions, so everyone else should do it for you.

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Josh Berkus 2015-06-25 17:40:02 Re: Oh, this is embarrassing: init file logic is still broken
Previous Message Tom Lane 2015-06-25 16:57:33 Re: Serialization errors in Postgres 9.4.0