Re: Passphrase protected SSL key and reloads

Joe Conway <[email protected]>
Newsgroups gmane.comp.db.postgresql.devel.documentation
Message-ID <[email protected]>
(moved from Hackers to docs)

On 1/5/19 4:26 PM, Joe Conway wrote:
> On https://www.postgresql.org/docs/11/ssl-tcp.html it says:
> 
>   "Using a passphrase also disables the ability to change the server's
>    SSL configuration without a server restart."
> 
> But as of pg11 we have ssl_passphrase_command_supports_reload, which as
> I understand it should allow this if the passphrase command is not
> interactive. Per
> https://www.postgresql.org/docs/11/runtime-config-connection.html#GUC-SSL-PASSPHRASE-COMMAND-SUPPORTS-RELOAD
> 
>   "Setting this parameter to true might be appropriate if the passphrase
>    is obtained from a file, for example."
> 
> Am I misunderstanding, or was the former quote missed when updating the
> docs for pg11?

Since I am already thinking about pgsql-docs today -- any comment on this?

Joe

-- 
Crunchy Data - http://crunchydata.com
PostgreSQL Support for Secure Enterprises
Consulting, Training, & Open Source Development
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEg14x9eymXoJyHrH+N/L3QzX32GUFAlzARtsACgkQN/L3QzX3
2GWauA/9FIH536yT0wudiYyQ4Qi/Fcr18b3Tsxb2t/W2GezMt7Qt9LYYW0SejTlD
9s7JCvuf60261H5rO+/rYxYcZpoYXgDb3V+8p4YS6VDalojW0+a+6Y8gW1ZQ0pIO
IRuU4B7/hSU0MKqAV/gemhB36H1LNLYwfE4InvyT36Nz2rrNeH6yQQhKedvGxVbn
Ut7oOC8CP8N+c89pEBgQuTJy6rb8uloICTxPaPz1h02TaklysUvsXBKr7ST7BJIX
oUKycu0Avydwco/Uh7oWo5iwk6eTzBu8hSZh32htUPj+mMd1JroPPXnREcBQmGMA
1Dl62O2EQZFobJrRwqF2W31lpQNUJMpZkpskezvYdtapiMzZBFvz/q6ngW/Uog3C
yAjlMW7K2JxZo5KB9qiRZvB6C2IGXg5PVCQqcGqD+GTle82rOMtUsnFmBHasgo6H
nRP8PCVU0rPzPFYxTQ/kEye+1vhCb0mXVqnwE+60UrBZuOdl/hML0qUN0pcz27Ac
DUa0RGduKwpxg9ll13WqQUyByQvHgkj41JAWzxWk076Pob1tSj4seDbsL4AUDPb7
cLqrimbzdqiOdbpTFjfivC1BqfRXqEaD2dtjIjp5QvKJj7Xeyv25fIu9D2PjB1/d
bgrYLVjoiDCQamDdDM9J+tuRM5KuU+rJWLBBV+yqs13pu7nBCdQ=
=tx7x
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.