Re: openssl heartbleed

From: Ovnicraft <ovnicraft(at)gmail(dot)com>
To: Gabriel E(dot) Sánchez Martínez <gabrielesanchez(at)gmail(dot)com>
Cc: Postgres General <pgsql-general(at)postgresql(dot)org>
Subject: Re: openssl heartbleed
Date: 2014-04-09 17:30:53
Message-ID: CA+16coMT2u2bkxqH4jV_i1+VZZLrPn_4xR4c1=Y7habMwRoBFw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Wed, Apr 9, 2014 at 10:54 AM, "Gabriel E. Sánchez Martínez" <
gabrielesanchez(at)gmail(dot)com> wrote:

> Hi all,
>
> Our server is running Ubuntu Server 13.10 (we will soon upgrade to 14.04)
> and PostgreSQL 9.1. We use certificates for all client authentication on
> remote connections. The server certificate is self-signed. In light of
> the heartbleed bug, should we create a new server certificate and replace
> all client certificates? My guess is yes.
>

I highly recommend you, update your server, revoke the certificates and
regenerate them.

Regards,

>
> Regards,
> Gabriel
>
>
> --
> Sent via pgsql-general mailing list (pgsql-general(at)postgresql(dot)org)
> To make changes to your subscription:
> http://www.postgresql.org/mailpref/pgsql-general
>

--
Cristian Salamea
@ovnicraft

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Paul Jungwirth 2014-04-09 19:28:14 Refresh Postgres SSL certs?
Previous Message Steve Crawford 2014-04-09 17:23:40 Re: openssl heartbleed