Magnus asked me for this, when the subject came up on IRC. This is a
longstanding ignored issue, for example
http://archives.postgresql.org/message-id/slrnemslp5.2rcr.andrew+non...@atlantis.supernews.net
http://archives.postgresql.org/message-id/15d55918-fa9c-4e6a-ba15-bdc9142a6...@contegix.com

-- 
Andrew (irc:RhodiumToad)

Index: src/backend/libpq/be-secure.c
===================================================================
RCS file: /projects/cvsroot/pgsql/src/backend/libpq/be-secure.c,v
retrieving revision 1.90
diff -c -r1.90 be-secure.c
*** src/backend/libpq/be-secure.c	28 Jan 2009 15:06:47 -0000	1.90
--- src/backend/libpq/be-secure.c	8 May 2009 21:30:43 -0000
***************
*** 729,737 ****
  		/*
  		 * Load and verify certificate and private key
  		 */
! 		if (SSL_CTX_use_certificate_file(SSL_context,
! 										  SERVER_CERT_FILE,
! 										  SSL_FILETYPE_PEM) != 1)
  			ereport(FATAL,
  					(errcode(ERRCODE_CONFIG_FILE_ERROR),
  				  errmsg("could not load server certificate file \"%s\": %s",
--- 729,736 ----
  		/*
  		 * Load and verify certificate and private key
  		 */
! 		if (SSL_CTX_use_certificate_chain_file(SSL_context,
! 										  SERVER_CERT_FILE) != 1)
  			ereport(FATAL,
  					(errcode(ERRCODE_CONFIG_FILE_ERROR),
  				  errmsg("could not load server certificate file \"%s\": %s",
-- 
Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-hackers

Reply via email to