Commit Graph

118 Commits (91d6429fad55f0e440643993754216614a9f6b11)

Author SHA1 Message Date
Heikki Linnakangas 3e60e956b0 Fix check for 'outlen' return from SSL_select_next_proto() 2 years ago
Heikki Linnakangas 91044ae4ba Send ALPN in TLS handshake, require it in direct SSL connections 2 years ago
Daniel Gustafsson 697f8d266c Revert "Add notBefore and notAfter to SSL cert info display" 2 years ago
Daniel Gustafsson 6acb0a628e Add notBefore and notAfter to SSL cert info display 2 years ago
Tom Lane 453c468737 Cope with a deficiency in OpenSSL 3.x's error reporting. 2 years ago
Bruce Momjian 29275b1d17 Update copyright for 2024 2 years ago
Tom Lane 0a5c46a7a4 Be more wary about OpenSSL not setting errno on error. 2 years ago
Michael Paquier 8d9978a717 Apply quotes more consistently to GUC names in logs 2 years ago
Tom Lane c82207a548 Use BIO_{get,set}_app_data instead of BIO_{get,set}_data. 2 years ago
Daniel Gustafsson 5f3aa309a8 Avoid potential pfree on NULL on OpenSSL errors 2 years ago
Daniel Gustafsson 29a0ccbce9 Revert "Add notBefore and notAfter to SSL cert info display" 2 years ago
Daniel Gustafsson 75ec5e7bec Add notBefore and notAfter to SSL cert info display 2 years ago
Michael Paquier 8e278b6576 Remove support for OpenSSL 1.0.1 3 years ago
Tom Lane 0245f8db36 Pre-beta mechanical code beautification. 3 years ago
Peter Eisentraut 803b4a26ca Remove stray mid-sentence tabs in comments 3 years ago
Daniel Gustafsson 7ab1bc2939 Fix outdated references to guc.c 3 years ago
Michael Paquier 9244c11afe Fix handling of SCRAM-SHA-256's channel binding with RSA-PSS certificates 3 years ago
Bruce Momjian c8e1ba736b Update copyright for 2023 3 years ago
Peter Geoghegan a601366a46 Harmonize more parameter names in bulk. 3 years ago
Peter Eisentraut 257eb57b50 Don't reflect unescaped cert data to the logs 3 years ago
Thomas Munro 2492fe49dc Remove configure probe for netinet/tcp.h. 3 years ago
Peter Eisentraut 3a0e385048 Log details for client certificate failures 3 years ago
Bruce Momjian 27b77ecf9f Update copyright for 2022 4 years ago
Tom Lane 1241fcbd7e Second attempt to silence SSL compile failures on hamerkop. 4 years ago
Tom Lane 24f9e49e43 Blind attempt to silence SSL compile failures on hamerkop. 4 years ago
Peter Eisentraut 4ac0f450b6 Message style improvements 4 years ago
Daniel Gustafsson 31f860a52b Set type identifier on BIO 4 years ago
Michael Paquier 01e6f1a842 Disallow SSL renegotiation 5 years ago
Tom Lane def5b065ff Initial pgindent and pgperltidy run for v14. 5 years ago
Andrew Dunstan 6d7a6feac4 Allow matching the DN of a client certificate for authentication 5 years ago
Tom Lane e835e89a0f Fix memory leak when rejecting bogus DH parameters. 5 years ago
Tom Lane 4b12ab18c9 Avoid corner-case memory leak in SSL parameter processing. 5 years ago
Michael Paquier f9264d1524 Remove support for SSL compression 5 years ago
Peter Eisentraut f5465fade9 Allow specifying CRL directory 5 years ago
Michael Paquier af0e79c8f4 Move SSL information callback earlier to capture more information 5 years ago
Bruce Momjian ca3b37487b Update copyright for 2021 5 years ago
Alvaro Herrera 52eec1c53a
Message style improvements 5 years ago
Magnus Hagander 13cfa02f77 Improve error handling in backend OpenSSL implementation 5 years ago
Tom Lane e1cc25f59a Fix list of SSL error codes for older OpenSSL versions. 6 years ago
Tom Lane b63dd3d88f Add hints about protocol-version-related SSL connection failures. 6 years ago
Michael Paquier 3fa44a3004 Fix comment in be-secure-openssl.c 6 years ago
Tom Lane fa27dd40d5 Run pgindent with new pg_bsd_indent version 2.1.1. 6 years ago
Tom Lane 5cbfce562f Initial pgindent and pgperltidy run for v13. 6 years ago
Michael Paquier e30b0b5cfa Fix check for conflicting SSL min/max protocol settings 6 years ago
Andrew Dunstan 896fcdb230 Provide a TLS init hook 6 years ago
Michael Paquier 79dfa8afb2 Add bound checks for ssl_min_protocol_version and ssl_max_protocol_version 6 years ago
Alvaro Herrera 4e89c79a52 Remove excess parens in ereport() calls 6 years ago
Michael Paquier ff8ca5fadd Add connection parameters to control SSL protocol min/max in libpq 6 years ago
Michael Paquier f7cd5896a6 Move OpenSSL routines for min/max protocol setting to src/common/ 6 years ago
Michael Paquier 7b283d0e1d Remove support for OpenSSL 0.9.8 and 1.0.0 6 years ago