Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commitc887ae4

Browse files
committed
Document that null ciphers are not recommended.
Mark Mielke
1 parentea63bf6 commitc887ae4

File tree

1 file changed

+13
-5
lines changed

1 file changed

+13
-5
lines changed

‎doc/src/sgml/runtime.sgml

Lines changed: 13 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
<!-- $PostgreSQL: pgsql/doc/src/sgml/runtime.sgml,v 1.399 2007/12/2903:44:34 momjian Exp $ -->
1+
<!-- $PostgreSQL: pgsql/doc/src/sgml/runtime.sgml,v 1.400 2007/12/2904:27:02 momjian Exp $ -->
22

33
<chapter Id="runtime">
44
<title>Operating System Environment</title>
@@ -1604,12 +1604,20 @@ $ <userinput>kill -INT `head -1 /usr/local/pgsql/data/postmaster.pid`</userinput
16041604
ciphers can be specified in the <productname>OpenSSL</productname>
16051605
configuration file, you can specify ciphers specifically for use by
16061606
the database server by modifying <xref linkend="guc-ssl-ciphers"> in
1607-
<filename>postgresql.conf</>. It is possible to have authentication
1608-
without the overhead of encryption by using <literal>NULL-SHA</> or
1609-
<literal>NULL-MD5</> ciphers. However, a man-in-the-middle could read
1610-
and pass communications between client and server.
1607+
<filename>postgresql.conf</>.
16111608
</para>
16121609

1610+
<note>
1611+
<para>
1612+
It is possible to have authentication without encryption overhead by
1613+
using <literal>NULL-SHA</> or <literal>NULL-MD5</> ciphers. However,
1614+
a man-in-the-middle could read and pass communications between client
1615+
and server. Also, encryption overhead is minimal compared to the
1616+
overhead of authentication. For these reasons NULL ciphers are not
1617+
recommended.
1618+
</para>
1619+
</note>
1620+
16131621
<para>
16141622
To start in <acronym>SSL</> mode, the files <filename>server.crt</>
16151623
and <filename>server.key</> must exist in the server's data directory.

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp