    > Well what's required to "configure SSL" anyways? If you don't have
    > verify-ca set or a root canal cert present then the server just needs a
    > certificate -- any certificate. Can the server just cons one up on demand
    > (or server startup or initdb)?

    Hmm, good old "snake oil certificate" approach.  Yeah, we could probably
    have initdb create a cert all the time.  I had memories of this taking
    an undue amount of time, but it seems pretty fast on a modern server.

It can still take a very significant amount of time in some virtual
environments, due to lack of entropy. And virtual environments aren't
exactly uncommon these days...

What expire time would you chose for the certificate? One year? Two years?
Which tool is going to re-generate your new cert, once this one expires? You don't want to run initdb again ...


