ssl: Use the correct feature macros for TLS protocol support

Our test for if the underlying TLS library supported a specific
version tested against the TLSX_Y_VERSION set of macros. These
are however always defined, regardless of if the library was
built without support for the specific protocol version.  Fix
by using the feature test macros OPENSSL_NO_TLSX_Y which are
intended for this usecase.

The previous coding held no risk of protocol downgrade against
the underlying library, a library not supporting the protocol
version selected would simply error out as the feature isn't
available.  This can be easily verified using a modern version
of LibreSSL, which in version 3.8 disabled TLS1 and 1.1 by
default.  Once we bump our minimum supported version of LibreSSL
to 3.8+ we can add a test for this.

Author: Daniel Gustafsson <[email protected]>
Reviewed-by: Tristan Partin <[email protected]>
Reviewed-by: Andreas Karlsson <[email protected]>
Reviewed-by: Yilin Zhang <[email protected]>
Discussion: https://postgr.es/m/[email protected]

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/1ce49fab6026ba53dbe29576a53e67fe9e1557f7

Modified Files
--------------
src/backend/libpq/be-secure-openssl.c    | 10 +++++++---
src/interfaces/libpq/fe-secure-openssl.c |  8 +++++---
2 files changed, 12 insertions(+), 6 deletions(-)

Reply via email to