Re: SSL - automatic entry of certificate passphrase in PostgreSQL 10?

"Vasanth Kumar Pediseti" <[email protected]> 6 Dec 2019 21:45:06 -0000
Newsgroups gmane.comp.db.postgresql.admin
Message-ID <1575638743.S.6338.20268.f5-224-118.1575668706.23383@webmail.rediffmail.com>
--=_b3df91cb9580453a5661ec9420372e41
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="UTF-8"

PLEASE STOP SENDING&nbsp; - NOT INTERESTEDFrom: Martin Goodson &lt;[email protected]&gt;Sent: Fri, 06 Dec 2019 18:55:43To: pgsql-admin &lt;[email protected]&gt;Subject: SSL - automatic entry of certificate passphrase in PostgreSQL 10?Hello.Apologies if this is an easy one, I&#39;ve been looking around but clearlymy google-fu may be weak :)I&#39;ve recently been asked to enable ssl support on one of our PostgreSQL10 databases, which I&#39;ve done. However, the certificate I was givenappears to have been generated using a passphrase, and now during serverstart I&#39;m being prompted (as expected) for that passphrase.I&#39;m concerned that this is going to impact the automatic (re)start ofthe database after server shutdowns, crashes etc. I understand thatthere is functionality 
 to support this in PostgreSQL 11 with thessl_passphrase_command parameter, but I was wondering if there&#39;s a wayto emulate this in PostgreSQL 10 or any kind of workaround?Or am I stuck with either requesting a new certificate without thepassphrase or going to PostgreSQL 11?For information, it&#39;s a PostgreSQL 10.5 cluster hosted on a VM runningRHEL 7.6.Many thanks!--Martin GoodsonIn bed above we&#39;re deep asleep,While greater love lies further deep.This dream must end, the world must know,We all depend on the beast below.&nbsp;
--=_b3df91cb9580453a5661ec9420372e41
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="UTF-8"

<strong>PLEASE STOP SENDING&nbsp; - NOT INTERESTED</strong><br /><br />From=
: Martin Goodson &lt;[email protected]&gt;<br />Sent: Fri, 06 Dec 201=
9 18:55:43<br />To: pgsql-admin &lt;[email protected]&gt;<br />Sub=
ject: SSL - automatic entry of certificate passphrase in PostgreSQL 10?<br =
/><br />Hello.<br /><br />Apologies if this is an easy one, I&#39;ve been l=
ooking around but clearly<br />my google-fu may be weak :)<br /><br />I&#39=
;ve recently been asked to enable ssl support on one of our PostgreSQL<br /=
>10 databases, which I&#39;ve done. However, the certificate I was given<br=
 />appears to have been generated using a passphrase, and now during server=
<br />start I&#39;m being prompted (as expected) for that passphrase.<br />=
<br />I&#39;m concerned that this is going to impact the automatic (re)star=
t of<br />the database after server shutdowns, crashes etc. I understand th=
at<br />there is functionality to support this in PostgreSQL 11 with the<br=
 />ssl_passphrase_command parameter, but I was wondering if there&#39;s a w=
ay<br />to emulate this in PostgreSQL 10 or any kind of workaround?<br /><b=
r />Or am I stuck with either requesting a new certificate without the<br /=
>passphrase or going to PostgreSQL 11?<br /><br />For information, it&#39;s=
 a PostgreSQL 10.5 cluster hosted on a VM running<br />RHEL 7.6.<br /><br /=
>Many thanks!<br /><br />--<br />Martin Goodson<br /><br />In bed above we&=
#39;re deep asleep,<br />While greater love lies further deep.<br />This dr=
eam must end, the world must know,<br />We all depend on the beast below.<b=
r /><br /><br />&nbsp;<br>
--=_b3df91cb9580453a5661ec9420372e41--