Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-24 Thread Magnus Hagander
On Fri, Sep 23, 2011 at 16:44, Alvaro Herrera alvhe...@commandprompt.com wrote: Excerpts from Magnus Hagander's message of vie sep 23 11:31:37 -0300 2011: On Fri, Sep 23, 2011 at 15:55, Alvaro Herrera alvhe...@commandprompt.com wrote: This seems strange to me.  Why not have a second option

[HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Magnus Hagander
On Wed, Aug 31, 2011 at 11:59, Srinivas Aji srinivas@emc.com wrote: The following bug has been logged online: Bug reference:      6189 Logged by:          Srinivas Aji Email address:      srinivas@emc.com PostgreSQL version: 9.0.4 Operating system:   Linux Description:        

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Lou Picciano
From: Magnus Hagander mag...@hagander.net To: Srinivas Aji srinivas@emc.com Cc: PostgreSQL-development pgsql-hackers@postgresql.org Sent: Friday, September 23, 2011 7:28:09 AM Subject: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Magnus Hagander
On Fri, Sep 23, 2011 at 14:35, Lou Picciano loupicci...@comcast.net wrote: On Wed, Aug 31, 2011 at 11:59, Srinivas Aji srinivas@emc.com wrote: The following bug has been logged online: Bug reference:      6189 Logged by:          Srinivas Aji Email address:      srinivas@emc.com

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Robert Haas
On Fri, Sep 23, 2011 at 8:38 AM, Magnus Hagander mag...@hagander.net wrote: On Fri, Sep 23, 2011 at 14:35, Lou Picciano loupicci...@comcast.net wrote: On Wed, Aug 31, 2011 at 11:59, Srinivas Aji srinivas@emc.com wrote: The following bug has been logged online: Bug reference:      6189

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Tom Lane
Magnus Hagander mag...@hagander.net writes: I looked at this again, and I'm pretty sure we did this intentionally. Yeah, we did. Or should we just update the documentation to mention how this works? +1 for doc change only. I think the behavior was thought through carefully, and the wording

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Lou Picciano
From: Magnus Hagander mag...@hagander.net To: Lou Picciano loupicci...@comcast.net Cc: PostgreSQL-development pgsql-hackers@postgresql.org, Srinivas Aji srinivas@emc.com Sent: Friday, September 23, 2011 8:38:00 AM Subject: Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Magnus Hagander
On Fri, Sep 23, 2011 at 14:49, Robert Haas robertmh...@gmail.com wrote: On Fri, Sep 23, 2011 at 8:38 AM, Magnus Hagander mag...@hagander.net wrote: On Fri, Sep 23, 2011 at 14:35, Lou Picciano loupicci...@comcast.net wrote: On Wed, Aug 31, 2011 at 11:59, Srinivas Aji srinivas@emc.com wrote:

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Alvaro Herrera
Excerpts from Magnus Hagander's message of vie sep 23 10:39:46 -0300 2011: On Fri, Sep 23, 2011 at 14:49, Robert Haas robertmh...@gmail.com wrote: On Fri, Sep 23, 2011 at 8:38 AM, Magnus Hagander mag...@hagander.net wrote: On Fri, Sep 23, 2011 at 14:35, Lou Picciano

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Magnus Hagander
On Fri, Sep 23, 2011 at 15:55, Alvaro Herrera alvhe...@commandprompt.com wrote: Excerpts from Magnus Hagander's message of vie sep 23 10:39:46 -0300 2011: On Fri, Sep 23, 2011 at 14:49, Robert Haas robertmh...@gmail.com wrote: On Fri, Sep 23, 2011 at 8:38 AM, Magnus Hagander

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-23 Thread Alvaro Herrera
Excerpts from Magnus Hagander's message of vie sep 23 11:31:37 -0300 2011: On Fri, Sep 23, 2011 at 15:55, Alvaro Herrera alvhe...@commandprompt.com wrote: This seems strange to me.  Why not have a second option to let the user indicate the desired SSL verification?

[HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-12 Thread David Fetter
On Wed, Aug 31, 2011 at 09:59:18AM +, Srinivas Aji wrote: The following bug has been logged online: Bug reference: 6189 Logged by: Srinivas Aji Email address: srinivas@emc.com PostgreSQL version: 9.0.4 Operating system: Linux Description:libpq:

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-12 Thread Magnus Hagander
On Mon, Sep 12, 2011 at 19:21, David Fetter da...@fetter.org wrote: On Wed, Aug 31, 2011 at 09:59:18AM +, Srinivas Aji wrote: The following bug has been logged online: Bug reference:      6189 Logged by:          Srinivas Aji Email address:      srinivas@emc.com PostgreSQL version:

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-12 Thread David Fetter
On Mon, Sep 12, 2011 at 07:37:23PM +0200, Magnus Hagander wrote: On Mon, Sep 12, 2011 at 19:21, David Fetter da...@fetter.org wrote: On Wed, Aug 31, 2011 at 09:59:18AM +, Srinivas Aji wrote: The following bug has been logged online: Bug reference:      6189 Logged by:          

Re: [HACKERS] Re: [BUGS] BUG #6189: libpq: sslmode=require verifies server certificate if root.crt is present

2011-09-12 Thread Robert Haas
On Mon, Sep 12, 2011 at 2:20 PM, David Fetter da...@fetter.org wrote: Well, too much checking, classically, is a source of denial of service attacks.  It's not a super likely source, but it's a source, and it'd be better to fix it than leave it lie. :) You forgot to attach the patch. --