agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Daniel Gustafsson <dgustafsson@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: ssl: Use the correct feature macros for TLS protocol support
Date: Wed, 29 Jul 2026 19:27:35 +0000
Message-ID: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org> (raw)

ssl: Use the correct feature macros for TLS protocol support

Our test for if the underlying TLS library supported a specific
version tested against the TLSX_Y_VERSION set of macros. These
are however always defined, regardless of if the library was
built without support for the specific protocol version.  Fix
by using the feature test macros OPENSSL_NO_TLSX_Y which are
intended for this usecase.

The previous coding held no risk of protocol downgrade against
the underlying library, a library not supporting the protocol
version selected would simply error out as the feature isn't
available.  This can be easily verified using a modern version
of LibreSSL, which in version 3.8 disabled TLS1 and 1.1 by
default.  Once we bump our minimum supported version of LibreSSL
to 3.8+ we can add a test for this.

Author: Daniel Gustafsson <daniel@yesql.se>
Reviewed-by: Tristan Partin <tristan@partin.io>
Reviewed-by: Andreas Karlsson <andreas@proxel.se>
Reviewed-by: Yilin Zhang <jiezhilove@126.com>
Discussion: https://postgr.es/m/68B9881D-DAA8-467D-A251-C96E98E57BA0@yesql.se

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/1ce49fab6026ba53dbe29576a53e67fe9e1557f7

Modified Files
--------------
src/backend/libpq/be-secure-openssl.c    | 10 +++++++---
src/interfaces/libpq/fe-secure-openssl.c |  8 +++++---
2 files changed, 12 insertions(+), 6 deletions(-)



Message-ID: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org>
Permalink:  ../E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: dgustafsson@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: ssl: Use the correct feature macros for TLS protocol support
  In-Reply-To: <E1wp9wF-00000000qIx-1gZr@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox