agora inbox for pgsql-committers@postgresql.org
help / color / mirror / Atom feedFrom: Daniel Gustafsson <dgustafsson@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: ssl: Use the correct feature macros for TLS protocol support
Date: Wed, 29 Jul 2026 19:27:35 +0000
Message-ID: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org> (raw)
ssl: Use the correct feature macros for TLS protocol support
Our test for if the underlying TLS library supported a specific
version tested against the TLSX_Y_VERSION set of macros. These
are however always defined, regardless of if the library was
built without support for the specific protocol version. Fix
by using the feature test macros OPENSSL_NO_TLSX_Y which are
intended for this usecase.
The previous coding held no risk of protocol downgrade against
the underlying library, a library not supporting the protocol
version selected would simply error out as the feature isn't
available. This can be easily verified using a modern version
of LibreSSL, which in version 3.8 disabled TLS1 and 1.1 by
default. Once we bump our minimum supported version of LibreSSL
to 3.8+ we can add a test for this.
Author: Daniel Gustafsson <daniel@yesql.se>
Reviewed-by: Tristan Partin <tristan@partin.io>
Reviewed-by: Andreas Karlsson <andreas@proxel.se>
Reviewed-by: Yilin Zhang <jiezhilove@126.com>
Discussion: https://postgr.es/m/68B9881D-DAA8-467D-A251-C96E98E57BA0@yesql.se
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/1ce49fab6026ba53dbe29576a53e67fe9e1557f7
Modified Files
--------------
src/backend/libpq/be-secure-openssl.c | 10 +++++++---
src/interfaces/libpq/fe-secure-openssl.c | 8 +++++---
2 files changed, 12 insertions(+), 6 deletions(-)
Message-ID: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org>
Permalink: ../E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org/
Also on: postgresql.org/message-id/E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-committers@postgresql.org
Cc: dgustafsson@postgresql.org, pgsql-committers@lists.postgresql.org
Subject: Re: pgsql: ssl: Use the correct feature macros for TLS protocol support
In-Reply-To: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox