ssl: Use the correct feature macros for TLS protocol support Our test for if the underlying TLS library supported a specific version tested against the TLSX_Y_VERSION set of macros. These are however always defined, regardless of if the library was built without support for the specific protocol version. Fix by using the feature test macros OPENSSL_NO_TLSX_Y which are intended for this usecase.
The previous coding held no risk of protocol downgrade against the underlying library, a library not supporting the protocol version selected would simply error out as the feature isn't available. This can be easily verified using a modern version of LibreSSL, which in version 3.8 disabled TLS1 and 1.1 by default. Once we bump our minimum supported version of LibreSSL to 3.8+ we can add a test for this. Author: Daniel Gustafsson <[email protected]> Reviewed-by: Tristan Partin <[email protected]> Reviewed-by: Andreas Karlsson <[email protected]> Reviewed-by: Yilin Zhang <[email protected]> Discussion: https://postgr.es/m/[email protected] Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/1ce49fab6026ba53dbe29576a53e67fe9e1557f7 Modified Files -------------- src/backend/libpq/be-secure-openssl.c | 10 +++++++--- src/interfaces/libpq/fe-secure-openssl.c | 8 +++++--- 2 files changed, 12 insertions(+), 6 deletions(-)
