SSL cert chains patch
Magnus asked me for this, when the subject came up on IRC. This is a
longstanding ignored issue, for example
http://archives.postgresql.org/message-id/slrnemslp5.2rcr.andrew+nonews@atlantis.supernews.net
http://archives.postgresql.org/message-id/15D55918-FA9C-4E6A-BA15-BDC9142A6C44@contegix.com
--
Andrew (irc:RhodiumToad)
Attachments:
sslchain.patchtext/x-patchDownload
Index: src/backend/libpq/be-secure.c
===================================================================
RCS file: /projects/cvsroot/pgsql/src/backend/libpq/be-secure.c,v
retrieving revision 1.90
diff -c -r1.90 be-secure.c
*** src/backend/libpq/be-secure.c 28 Jan 2009 15:06:47 -0000 1.90
--- src/backend/libpq/be-secure.c 8 May 2009 21:30:43 -0000
***************
*** 729,737 ****
/*
* Load and verify certificate and private key
*/
! if (SSL_CTX_use_certificate_file(SSL_context,
! SERVER_CERT_FILE,
! SSL_FILETYPE_PEM) != 1)
ereport(FATAL,
(errcode(ERRCODE_CONFIG_FILE_ERROR),
errmsg("could not load server certificate file \"%s\": %s",
--- 729,736 ----
/*
* Load and verify certificate and private key
*/
! if (SSL_CTX_use_certificate_chain_file(SSL_context,
! SERVER_CERT_FILE) != 1)
ereport(FATAL,
(errcode(ERRCODE_CONFIG_FILE_ERROR),
errmsg("could not load server certificate file \"%s\": %s",
Andrew Gierth wrote:
Magnus asked me for this, when the subject came up on IRC. This is a
longstanding ignored issue, for example
http://archives.postgresql.org/message-id/slrnemslp5.2rcr.andrew+nonews@atlantis.supernews.net
http://archives.postgresql.org/message-id/15D55918-FA9C-4E6A-BA15-BDC9142A6C44@contegix.com
Applied, thanks!
--
Magnus Hagander
Self: http://www.hagander.net/
Work: http://www.redpill-linpro.com/
Magnus Hagander wrote:
Andrew Gierth wrote:
Magnus asked me for this, when the subject came up on IRC. This is a
longstanding ignored issue, for example
http://archives.postgresql.org/message-id/slrnemslp5.2rcr.andrew+nonews@atlantis.supernews.net
http://archives.postgresql.org/message-id/15D55918-FA9C-4E6A-BA15-BDC9142A6C44@contegix.comApplied, thanks!
Shouldn't this be backpatched?
--
Alvaro Herrera http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.
Alvaro Herrera <alvherre@commandprompt.com> writes:
Magnus Hagander wrote:
Applied, thanks!
Shouldn't this be backpatched?
It looks like a feature change to me ...
regards, tom lane