Tom Lane wrote:
> > Add SSL CRL support to libpq.  Recently added to the backend.
> Surely this patch requires a documentation update.

Oh, I didn't realize the libpq documentation went into that detail, but
it does.  Patch attached and applied.

     The SSL connection will
     fail if the server does not present a certificate; therefore, to
     use this feature the server must also have a <filename>root.crt</> file.
+    Certificate Revocation List (CRL) entries are also checked if the file
+    <filename>~/.postgresql/root.crl</filename> exists (%APPDATA%\postgresql\root.crl
+    on Microsoft Windows).
