From: | Robert Haas <robertmhaas(at)gmail(dot)com> |
---|---|
To: | Michael Paquier <michael(dot)paquier(at)gmail(dot)com> |
Cc: | Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>, Stephen Frost <sfrost(at)snowman(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Álvaro Hernández Tortosa <aht(at)8kdata(dot)com>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: [JDBC] Channel binding support for SCRAM-SHA-256 |
Date: | 2017-10-02 16:30:25 |
Message-ID: | CA+TgmoYwnuQ7vNu03ahUgr5VvJysEDdXhwD87-LM6kGEW+Ej9g@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers pgsql-jdbc |
On Fri, Sep 15, 2017 at 6:29 PM, Michael Paquier
<michael(dot)paquier(at)gmail(dot)com> wrote:
> I would like to point out that per the RFC, if the client attempts a
> SSL connection with SCRAM and that the server supports channel
> binding, then it has to publish the SASL mechanism for channel
> binding, aka SCRAM-PLUS. If the client tries to force the use of SCRAM
> even if SCRAM-PLUS is specified, this is seen as a downgrade attack by
> the server which must reject the connection. So this parameter has
> meaning only if you try to connect to a PG10 server using a PG11
> client (assuming that channel binding gets into PG11). If you connect
> with a PG11 client to a PG11 server with SSL, the server publishes
> SCRAM-PLUS, the client has to use it, hence this turns out to make
> cbind=disable and prefer meaningless in the long-term. If the client
> does not use SSL, then there is no channel binding, and cbind=require
> loses its value. So cbind's fate is actually linked to sslmode.
That seems problematic. What if the client supports SCRAM but not
channel binding?
--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company
From | Date | Subject | |
---|---|---|---|
Next Message | Robert Haas | 2017-10-02 16:36:02 | Re: issue: record or row variable cannot be part of multiple-item INTO list |
Previous Message | Tom Lane | 2017-10-02 16:28:59 | Re: issue: record or row variable cannot be part of multiple-item INTO list |
From | Date | Subject | |
---|---|---|---|
Next Message | Michael Paquier | 2017-10-03 01:31:29 | Re: [JDBC] Channel binding support for SCRAM-SHA-256 |
Previous Message | Daniel Gustafsson | 2017-10-01 22:25:48 | Re: Statement-level rollback |