Re: Allow 'sslkey' and 'sslcert' in postgres_fdw user mappings

Christoph Berg <[email protected]>
Newsgroups gmane.comp.db.postgresql.devel.general
Message-ID <[email protected]>
Re: To Andrew Dunstan 2020-01-09 <[email protected]>
> I believe the options are still used in that case
> for creating connections, even when that means the remote server isn't
> set up for cert auth, which needs password_required=false to succeed.

They are indeed:

stat("/var/lib/postgresql/.postgresql/root.crt", 0x7ffcff3e2bb0) = -1 ENOENT (Datei oder Verzeichnis nicht gefunden)
stat("/foo", 0x7ffcff3e2bb0)            = -1 ENOENT (Datei oder Verzeichnis nicht gefunden)
      ^^^^ sslcert

I'm not sure if that could be exploited in any way, but let's just
forbid it.

Christoph
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.