• Peter Eisentraut's avatar
    SSL: Add configuration option to prefer server cipher order · ef326752
    Peter Eisentraut authored
    By default, OpenSSL (and SSL/TLS in general) lets the client cipher
    order take priority.  This is OK for browsers where the ciphers were
    tuned, but few PostgreSQL client libraries make the cipher order
    configurable.  So it makes sense to have the cipher order in
    postgresql.conf take priority over client defaults.
    
    This patch adds the setting "ssl_prefer_server_ciphers" that can be
    turned on so that server cipher order is preferred.  Per discussion,
    this now defaults to on.
    
    From: Marko Kreen <markokr@gmail.com>
    Reviewed-by: default avatarAdrian Klaver <adrian.klaver@gmail.com>
    ef326752
config.sgml 293 KB