On Thu, Jun 28, 2018 at 09:35:57AM +0200, Magnus Hagander wrote: > No, we absolutely still have SCRAM channel binding. > > *libpq* has no way to *enforce* it, meaning it always acts like our default > SSL > config which is "use it if available but if it's not then silently accept the > downgrade". From a security perspective, it's just as bad as our default ssl > config, but unlike ssl you can't configure a requirement in 11.
I think we are much more likely to be able to force channel binding by default since there is no need to configure a certificate authority. -- Bruce Momjian <br...@momjian.us> http://momjian.us EnterpriseDB http://enterprisedb.com + As you are, so once was I. As I am, so you will be. + + Ancient Roman grave inscription +