Re: ssl connection issues

From: Dave Cramer <pg(at)fastcrypt(dot)com>
To: Craig Ringer <craig(at)2ndquadrant(dot)com>
Cc: gbulfon(at)sonicle(dot)com, pgsql-jdbc(at)lists(dot)postgresql(dot)org
Subject: Re: ssl connection issues
Date: 2018-09-14 10:20:08
Message-ID: CADK3HHJBkGxLxn3UhRG7NVutce2wzywBJU5_+snJwUQo-P0m6w@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-jdbc

On Thu, 13 Sep 2018 at 11:10, Craig Ringer <craig(at)2ndquadrant(dot)com> wrote:

> On 13 September 2018 at 20:23, Gabriele Bulfon <gbulfon(at)sonicle(dot)com>
> wrote:
>
>> Hello,
>>
>> I recently configured Postgresql 9.0.9 with SSL only "on" and all its
>> needed server certificates.
>> I then created the client certificates and started working with them from
>> a windows client.
>>
>> At first I used them with tools like Navicat, just specified the 3 certs
>> files (key,crt and root.crt) in the ssl pane, worked fine.
>>
>> Then I tried with ODBC, placed the files in %APPDATA%/postgresql with
>> correct names (postgresql.key, postgresql.crt, root.crt), created the
>> connection and tested it, worked fine.
>>
>> Last I tried with jdbc, thinking it would have been so easy: I'm fighting
>> for 2 days with lots of different issues.
>> After some messing, I also finally discovered that, different from odbc,
>> it would look for a pk8 file (why this difference?).
>>
>
> AFAIK it's largely historical, and due to now-lifted limitations in JSSE.
>
> You should probably use sslfactory=org.postgresql.ssl.LibPQFactory and
> possibly specify explicit paths for the sslcert and sslkey parameters.
>
> This seems to be undocumented, unfortunately.
>

the default is LibPQFactory and it is fairly well documented.

https://jdbc.postgresql.org/documentation/head/connect.html#connection-parameters

If this is lacking please let me know. I will fix it.

Thanks
Dave Cramer

davec(at)postgresintl(dot)com
www.postgresintl.com

>

In response to

Responses

Browse pgsql-jdbc by date

  From Date Subject
Next Message Dave Cramer 2018-09-14 10:37:26 [pgjdbc/pgjdbc] 833a4a: attempt jdk 10 and postgresql 10 (#1298)
Previous Message Gabriele Bulfon 2018-09-14 07:26:26 Re: ssl connection issues