Re: SSL - automatic entry of certificate passphrase in PostgreSQL 10?
"Vasanth Kumar Pediseti" <[email protected]> 6 Dec 2019 21:45:06 -0000
| Newsgroups | gmane.comp.db.postgresql.admin |
|---|---|
| Message-ID | <1575638743.S.6338.20268.f5-224-118.1575668706.23383@webmail.rediffmail.com> |
--=_b3df91cb9580453a5661ec9420372e41 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="UTF-8" PLEASE STOP SENDING - NOT INTERESTEDFrom: Martin Goodson <[email protected]>Sent: Fri, 06 Dec 2019 18:55:43To: pgsql-admin <[email protected]>Subject: SSL - automatic entry of certificate passphrase in PostgreSQL 10?Hello.Apologies if this is an easy one, I've been looking around but clearlymy google-fu may be weak :)I've recently been asked to enable ssl support on one of our PostgreSQL10 databases, which I've done. However, the certificate I was givenappears to have been generated using a passphrase, and now during serverstart I'm being prompted (as expected) for that passphrase.I'm concerned that this is going to impact the automatic (re)start ofthe database after server shutdowns, crashes etc. I understand thatthere is functionality to support this in PostgreSQL 11 with thessl_passphrase_command parameter, but I was wondering if there's a wayto emulate this in PostgreSQL 10 or any kind of workaround?Or am I stuck with either requesting a new certificate without thepassphrase or going to PostgreSQL 11?For information, it's a PostgreSQL 10.5 cluster hosted on a VM runningRHEL 7.6.Many thanks!--Martin GoodsonIn bed above we're deep asleep,While greater love lies further deep.This dream must end, the world must know,We all depend on the beast below. --=_b3df91cb9580453a5661ec9420372e41 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset="UTF-8" <strong>PLEASE STOP SENDING - NOT INTERESTED</strong><br /><br />From= : Martin Goodson <[email protected]><br />Sent: Fri, 06 Dec 201= 9 18:55:43<br />To: pgsql-admin <[email protected]><br />Sub= ject: SSL - automatic entry of certificate passphrase in PostgreSQL 10?<br = /><br />Hello.<br /><br />Apologies if this is an easy one, I've been l= ooking around but clearly<br />my google-fu may be weak :)<br /><br />I'= ;ve recently been asked to enable ssl support on one of our PostgreSQL<br /= >10 databases, which I've done. However, the certificate I was given<br= />appears to have been generated using a passphrase, and now during server= <br />start I'm being prompted (as expected) for that passphrase.<br />= <br />I'm concerned that this is going to impact the automatic (re)star= t of<br />the database after server shutdowns, crashes etc. I understand th= at<br />there is functionality to support this in PostgreSQL 11 with the<br= />ssl_passphrase_command parameter, but I was wondering if there's a w= ay<br />to emulate this in PostgreSQL 10 or any kind of workaround?<br /><b= r />Or am I stuck with either requesting a new certificate without the<br /= >passphrase or going to PostgreSQL 11?<br /><br />For information, it's= a PostgreSQL 10.5 cluster hosted on a VM running<br />RHEL 7.6.<br /><br /= >Many thanks!<br /><br />--<br />Martin Goodson<br /><br />In bed above we&= #39;re deep asleep,<br />While greater love lies further deep.<br />This dr= eam must end, the world must know,<br />We all depend on the beast below.<b= r /><br /><br /> <br> --=_b3df91cb9580453a5661ec9420372e41--