Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sgCI6-00GZIK-8v for pgsql-docs@arkaria.postgresql.org; Tue, 20 Aug 2024 00:00:02 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sgCI4-004dUS-Ax for pgsql-docs@arkaria.postgresql.org; Tue, 20 Aug 2024 00:00:00 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sgCI4-004dRV-2w for pgsql-docs@lists.postgresql.org; Tue, 20 Aug 2024 00:00:00 +0000 Received: from momjian.us ([72.94.173.45]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sgCI1-000TsD-S8 for pgsql-docs@lists.postgresql.org; Mon, 19 Aug 2024 23:59:59 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=momjian.us; s=2024011501; h=In-Reply-To:Content-Type:MIME-Version:References:Message-ID: Subject:To:From:Date:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description; bh=/w549feD5pH5Q8v4LziX9YhoL/ddpg8Qz71ZWx+M3Ks=; b=CF5io p/6kbRBbDV9AiLAn+dri8Pt4Yp5ZSbp/11Ahj4mgXuPX0q1fDZR7tM4Uwzla6hmDBYHzZUhVxTbTB cHrxgYKpGpES6lPBan24/l7PHOHHlg8fW9iKW79G6WR6j87j/NUyvn4UBlLdZsv+mh0/sZRbwszyb GCCKxldTEzdlFN2MjSVJJJKpOoGAiEfHOm6X/eNOtFLR9oBp91eMAbXP6Om8lxgPfz6MJ7QgjnOS8 rrwvakXdmfb6vv8q8xHdNQLALjX1eoZJGDZpueJpLaXxRGlxlL0dky+gl0guv5qeE4B2tWsh4FTHl sIESrcz8H9e7yt/fLR2uVYigFCcaw==; Received: from bruce by momjian.us with local (Exim 4.96) (envelope-from ) id 1sgCI1-00FA4x-0i; Mon, 19 Aug 2024 19:59:57 -0400 Date: Mon, 19 Aug 2024 19:59:57 -0400 From: Bruce Momjian To: gerhardus.geldenhuis@gmail.com, pgsql-docs@lists.postgresql.org Subject: Re: Managing SSL Connections Message-ID: References: <172310655313.915373.10171638576433901136@wrigleys.postgresql.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <172310655313.915373.10171638576433901136@wrigleys.postgresql.org> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, Aug 8, 2024 at 08:42:33AM +0000, PG Doc comments form wrote: > The following documentation comment has been logged on the website: > > Page: https://www.postgresql.org/docs/16/ssl-tcp.html > Description: > > It would be handy to see documentation on the process of renewing a > certificate in terms of the impact it would have if you force clients to do > TLS connections. For example is there a way to load a new certificate whilst > the old one is still active to prevent outages or can this only be done in a > cluster setup? Does this blog post help you? https://momjian.us/main/blogs/pgblog/2020.html#July_17_2020 -- Bruce Momjian https://momjian.us EDB https://enterprisedb.com Only you can decide what is important to you.