Proposal: sslmode=tls-only

2021-12-24 Thread Keith Burdis
>From 53.2.9. SSL Session Encryption: > When SSL encryption can be performed, the server is expected to send only > the single S byte and then wait for the frontend to initiate an SSL > handshake. If additional bytes are available to read at this point, it > likely means that a man-in-the-middle

Re: Proposal: sslmode=tls-only

2021-12-24 Thread Keith Burdis
d without requesting SSL." [1] https://www.postgresql.org/docs/14/protocol-flow.html#id-1.10.5.7.11 On Fri, 24 Dec 2021 at 19:16, Andrew Dunstan wrote: > > On 12/24/21 09:08, Keith Burdis wrote: > > From 53.2.9. SSL Session Encryption: > > > > > > When SSL