Re: Supporting Subject Alternative Names for SSL connections on pgJDBC

From: Dave Cramer <pg(at)fastcrypt(dot)com>
To: "Higuchi, Daisuke" <higuchi(dot)daisuke(at)jp(dot)fujitsu(dot)com>
Cc: "pgsql-jdbc(at)postgresql(dot)org" <pgsql-jdbc(at)postgresql(dot)org>
Subject: Re: Supporting Subject Alternative Names for SSL connections on pgJDBC
Date: 2017-02-03 12:03:25
Message-ID: CADK3HH+E4BRvun2FZ5qpkDDh1rSHCtdZSf4OHi-Lk1fQ0Dpz7w@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-jdbc

Hi

Thanks for the patch! I will look at this.

Dave Cramer

davec(at)postgresintl(dot)com
www.postgresintl.com

On 3 February 2017 at 00:47, Higuchi, Daisuke <
higuchi(dot)daisuke(at)jp(dot)fujitsu(dot)com> wrote:

> Hello
>
> I re-issue old discussions about "Subject Alternative Names (SANs)".
> PostgreSQL can check SANs now [1], so pgJDBC should support this feature
> too, I think.
> Seeing past activity about SANs, I found the patch is contributed by Bruno
> [2] but no committed.
> I want to know developer's opinion about supporting SANs on pgJDBC.
>
> This feature is useful when failover is occurred.
> If failover is occurred, a single DNS name may point to different hosts
> after failover.
> Certainly we can use wildcards in the server common name, but this does
> not work if hosts name are complexed.
> On other words, common name "*.db.example.com" only works for names like "
> master.db.example.com", "slave.db.example.com",
> but not for the "example.com" and "db-master.example.com" and "
> db-slave.example.com" or other more complex naming schemas.
>
> I attached the initial patch (does not include unit test now), this is
> extracted from the patch created by Bruno and fixed a little.
>
> [1] https://www.postgresql.org/docs/current/static/libpq-ssl.html
> [2] https://www.postgresql.org/message-id/ja1a2v%24p2e%241%
> 40dough.gmane.org
>
> Regards,
> Daisuke, Higuchi
>
>
>
> --
> Sent via pgsql-jdbc mailing list (pgsql-jdbc(at)postgresql(dot)org)
> To make changes to your subscription:
> http://www.postgresql.org/mailpref/pgsql-jdbc
>
>

In response to

Browse pgsql-jdbc by date

  From Date Subject
Next Message Vladimir Sitnikov 2017-02-03 12:16:24 Re: postgresql-jdbc driver not respecting prepareThreshold=0
Previous Message Dave Cramer 2017-02-03 11:59:42 Re: postgresql-jdbc driver not respecting prepareThreshold=0