Re: [GENERAL] sslmode verify-ca and verify-full: essentialy the same?

2015-01-29 Thread Bruce Momjian
On Tue, Jan 27, 2015 at 02:55:56PM +0100, David Guyot wrote: Ah! So there was my error! Should be good to explain this in the official libpq documentation, don't you think? If I correctly read, the connection string as source of the hostname isn't explicit, there is only the mention that libpq

[GENERAL] sslmode verify-ca and verify-full: essentialy the same?

2015-01-27 Thread David Guyot
Hi, there. Firstly, as this is my first post on a PgSQL ML, I hope this ML is the good one for my question. I'm trying to secure further some PgSQL servers and am reading documentation about libpq sslmode option. I have a question about that: as I understand the internals of this option, the

Re: [GENERAL] sslmode verify-ca and verify-full: essentialy the same?

2015-01-27 Thread Magnus Hagander
On Tue, Jan 27, 2015 at 2:29 PM, David Guyot david.gu...@europecamions-interactive.com wrote: Hi, there. Firstly, as this is my first post on a PgSQL ML, I hope this ML is the good one for my question. I'm trying to secure further some PgSQL servers and am reading documentation about

Re: [GENERAL] sslmode verify-ca and verify-full: essentialy the same?

2015-01-27 Thread David Guyot
Ah! So there was my error! Should be good to explain this in the official libpq documentation, don't you think? If I correctly read, the connection string as source of the hostname isn't explicit, there is only the mention that libpq will check that the responding server is “the one I specify”.