Re: SSL (patch 5)
От | Bruce Momjian |
---|---|
Тема | Re: SSL (patch 5) |
Дата | |
Msg-id | 200206140439.g5E4dsK24610@candle.pha.pa.us обсуждение исходный текст |
Ответ на | SSL (patch 5) (Bear Giles <bgiles@coyotesong.com>) |
Список | pgsql-patches |
Bear, can you confirm that this patch should be rejected and that hopefully the SSL library will handle it in the future? --------------------------------------------------------------------------- Bear Giles wrote: > Patch to add initialization from entropy source, either a > file ($HOME/.postgresql/.rand, $DataDir/.rand) or the > /dev/urandom device. > > This is intended to reduce the ability of an attacker to > predict our "random" keys. > > The random file can be generated with the OpenSSL command: > openssl rand -out .rand 1024. > > Bear Content-Description: /tmp/patch5 [ Attachment, skipping... ] > > ---------------------------(end of broadcast)--------------------------- > TIP 4: Don't 'kill -9' the postmaster -- Bruce Momjian | http://candle.pha.pa.us pgman@candle.pha.pa.us | (610) 853-3000 + If your life is a hard drive, | 830 Blythe Avenue + Christ can be your backup. | Drexel Hill, Pennsylvania 19026
В списке pgsql-patches по дате отправления: