pg.ddx.io  pgsql-committers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Jacob Champion <jchampion@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: libpq: Add oauth_ca_file option to change CAs without debugging
Date: Mon, 30 Mar 2026 21:23:19 +0000
Message-ID: <E1w7K4s-002Csa-1u@gemulon.postgresql.org> (raw)

libpq: Add oauth_ca_file option to change CAs without debugging

PG18 hid the PGOAUTHCAFILE envvar behind PGOAUTHDEBUG=UNSAFE, because I
thought that any "real" production usage of private CA certificates
would have them added to the Curl system trust store. But there are use
cases, such as containerized environments, that prefer to manage custom
CA settings more granularly; some of them consider envvar configuration
of certificates to be standard practice.

Move PGOAUTHCAFILE out from under the debug flag, and add an
oauth_ca_file option to libpq to configure trusted CAs per connection.

Patch by Jonathan Gonzalez V., with some additional wordsmithing and
test organization by me.

Author: Jonathan Gonzalez V. <jonathan.abdiel@gmail.com>
Co-authored-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Zsolt Parragi <zsolt.parragi@percona.com>
Discussion: https://postgr.es/m/16a91d02795cb991963326a902afa764e4d721db.camel%40gmail.com

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/993368113c432832862db29f927c206dab0c0b8a

Modified Files
--------------
doc/src/sgml/libpq.sgml                            | 40 +++++++++++--
src/interfaces/libpq-oauth/oauth-curl.c            | 26 ++++-----
src/interfaces/libpq/fe-connect.c                  |  5 ++
src/interfaces/libpq/libpq-int.h                   |  1 +
src/test/modules/oauth_validator/t/001_server.pl   | 67 ++++++++++++++--------
src/test/modules/oauth_validator/t/OAuth/Server.pm |  2 +-
6 files changed, 96 insertions(+), 45 deletions(-)



Message-ID: <E1w7K4s-002Csa-1u@gemulon.postgresql.org>
Permalink:  ../E1w7K4s-002Csa-1u@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1w7K4s-002Csa-1u@gemulon.postgresql.org

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: jchampion@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: libpq: Add oauth_ca_file option to change CAs without debugging
  In-Reply-To: <E1w7K4s-002Csa-1u@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox