pg.ddx.io  pgsql-docs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
Document when ssl_prefer_server_ciphers went in
5+ messages / 3 participants
[nested] [flat]

* Document when ssl_prefer_server_ciphers went in
@ 2024-07-03 09:23 Daniel Gustafsson <daniel@yesql.se>
  2024-07-03 09:49 ` Re: Document when ssl_prefer_server_ciphers went in Peter Eisentraut <peter@eisentraut.org>
  2024-07-03 16:22 ` Re: Document when ssl_prefer_server_ciphers went in Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 2 replies; 5+ messages in thread

From: Daniel Gustafsson @ 2024-07-03 09:23 UTC (permalink / raw)
  To: pgsql-docs <pgsql-docs@lists.postgresql.org>

In the documentation for ssl_prefer_server_ciphers we only say it's not in
"older version" but we omit to specify it further.  Since it's a fairly
important setting for security I think it makes sense to add the version to
help users, as in the small attached diff (which also adds proper markup in the
paragraph while in there).

--
Daniel Gustafsson

Attachments:

  [application/octet-stream] ssl_prefer_cipher.diff (837B, ../../5D7E0F5E-E620-4D54-8788-66D421AC76F0@yesql.se/2-ssl_prefer_cipher.diff)
  download | inline diff:
diff --git a/doc/src/sgml/config.sgml b/doc/src/sgml/config.sgml
index 17d84bd321..82bf6dc76e 100644
--- a/doc/src/sgml/config.sgml
+++ b/doc/src/sgml/config.sgml
@@ -1443,11 +1443,12 @@ include_dir 'conf.d'
        </para>
 
        <para>
-        Older PostgreSQL versions do not have this setting and always use the
+        Older <productname>PostgreSQL</productname> versions do not have this setting and always use the
         client's preferences.  This setting is mainly for backward
         compatibility with those versions.  Using the server's preferences is
         usually better because it is more likely that the server is appropriately
-        configured.
+        configured.  This setting was introduced in
+        <productname>PostgreSQL<productname> 9.4.
        </para>
       </listitem>
      </varlistentry>

^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Document when ssl_prefer_server_ciphers went in
  2024-07-03 09:23 Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
@ 2024-07-03 09:49 ` Peter Eisentraut <peter@eisentraut.org>
  2024-07-04 10:17   ` Re: Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
  1 sibling, 1 reply; 5+ messages in thread

From: Peter Eisentraut @ 2024-07-03 09:49 UTC (permalink / raw)
  To: Daniel Gustafsson <daniel@yesql.se>; pgsql-docs <pgsql-docs@lists.postgresql.org>

On 03.07.24 11:23, Daniel Gustafsson wrote:
> In the documentation for ssl_prefer_server_ciphers we only say it's not in
> "older version" but we omit to specify it further.  Since it's a fairly
> important setting for security I think it makes sense to add the version to
> help users, as in the small attached diff (which also adds proper markup in the
> paragraph while in there).

Looks reasonable to me.

Would it make sense to remove the setting altogether?






^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Document when ssl_prefer_server_ciphers went in
  2024-07-03 09:23 Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
  2024-07-03 09:49 ` Re: Document when ssl_prefer_server_ciphers went in Peter Eisentraut <peter@eisentraut.org>
@ 2024-07-04 10:17   ` Daniel Gustafsson <daniel@yesql.se>
  0 siblings, 0 replies; 5+ messages in thread

From: Daniel Gustafsson @ 2024-07-04 10:17 UTC (permalink / raw)
  To: Peter Eisentraut <peter@eisentraut.org>; +Cc: pgsql-docs <pgsql-docs@lists.postgresql.org>

> On 3 Jul 2024, at 11:49, Peter Eisentraut <peter@eisentraut.org> wrote:
> 
> On 03.07.24 11:23, Daniel Gustafsson wrote:
>> In the documentation for ssl_prefer_server_ciphers we only say it's not in
>> "older version" but we omit to specify it further.  Since it's a fairly
>> important setting for security I think it makes sense to add the version to
>> help users, as in the small attached diff (which also adds proper markup in the
>> paragraph while in there).
> 
> Looks reasonable to me.

Thanks, pushed with the wording suggested to Tom downthread.

> Would it make sense to remove the setting altogether?

I wouldn't be opposed to it, I can't think of any legitimate usecase for it
outside of testing (it's very similar to ssl_max_protocol_version in that
sense).  On the other hand, it's very little code to carry and removing it
would cause churn for anyone who has it in their configuration management
system for provisioning.  Maybe it would make sense to remove it from the
sample config?

--
Daniel Gustafsson






^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Document when ssl_prefer_server_ciphers went in
  2024-07-03 09:23 Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
@ 2024-07-03 16:22 ` Tom Lane <tgl@sss.pgh.pa.us>
  2024-07-03 16:51   ` Re: Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
  1 sibling, 1 reply; 5+ messages in thread

From: Tom Lane @ 2024-07-03 16:22 UTC (permalink / raw)
  To: Daniel Gustafsson <daniel@yesql.se>; +Cc: pgsql-docs <pgsql-docs@lists.postgresql.org>

Daniel Gustafsson <daniel@yesql.se> writes:
> In the documentation for ssl_prefer_server_ciphers we only say it's not in
> "older version" but we omit to specify it further.  Since it's a fairly
> important setting for security I think it makes sense to add the version to
> help users, as in the small attached diff (which also adds proper markup in the
> paragraph while in there).

This could be shortened perhaps:

-        Older PostgreSQL versions do not have this setting and always use the
+        <productname>PostgreSQL</productname> versions before 9.4 do not have this setting and always use the

			regards, tom lane





^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Document when ssl_prefer_server_ciphers went in
  2024-07-03 09:23 Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
  2024-07-03 16:22 ` Re: Document when ssl_prefer_server_ciphers went in Tom Lane <tgl@sss.pgh.pa.us>
@ 2024-07-03 16:51   ` Daniel Gustafsson <daniel@yesql.se>
  0 siblings, 0 replies; 5+ messages in thread

From: Daniel Gustafsson @ 2024-07-03 16:51 UTC (permalink / raw)
  To: Tom Lane <tgl@sss.pgh.pa.us>; +Cc: pgsql-docs <pgsql-docs@lists.postgresql.org>

> On 3 Jul 2024, at 18:22, Tom Lane <tgl@sss.pgh.pa.us> wrote:
> 
> Daniel Gustafsson <daniel@yesql.se> writes:
>> In the documentation for ssl_prefer_server_ciphers we only say it's not in
>> "older version" but we omit to specify it further.  Since it's a fairly
>> important setting for security I think it makes sense to add the version to
>> help users, as in the small attached diff (which also adds proper markup in the
>> paragraph while in there).
> 
> This could be shortened perhaps:
> 
> -        Older PostgreSQL versions do not have this setting and always use the
> +        <productname>PostgreSQL</productname> versions before 9.4 do not have this setting and always use the

Good idea, that reads better.

--
Daniel Gustafsson






^ permalink  raw  reply  [nested|flat] 5+ messages in thread


end of thread, other threads:[~2024-07-04 10:17 UTC | newest]

Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-07-03 09:23 Document when ssl_prefer_server_ciphers went in Daniel Gustafsson <daniel@yesql.se>
2024-07-03 09:49 ` Peter Eisentraut <peter@eisentraut.org>
2024-07-04 10:17   ` Daniel Gustafsson <daniel@yesql.se>
2024-07-03 16:22 ` Tom Lane <tgl@sss.pgh.pa.us>
2024-07-03 16:51   ` Daniel Gustafsson <daniel@yesql.se>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox