pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Si, Evan <evansi.dev@gmail.com>
To: Dmitry Dolgov <9erthalion6@gmail.com>
Cc: Jacob Champion <jacob.champion@enterprisedb.com>
Cc: Daniel Gustafsson <daniel@yesql.se>
Cc: PostgreSQL Hackers <pgsql-hackers@postgresql.org>
Cc: Zsolt Parragi <zsolt.parragi@percona.com>
Subject: Re: Add ssl_(supported|shared)_groups to sslinfo
Date: Fri, 4 Sep 2026 16:20:27 -0700
Message-ID: <439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com> (raw)
In-Reply-To: <aprTMCAqd16B__py@ddolgov-thinkpadt14sgen1.rmtde.csb>
References: <CAOYmi+k7v6hP5nM7BQdKu37TJFi-X=d7_SDswZBV5q0awxPVYg@mail.gmail.com>
	<qyw7l5ztbqouluctxgbxc2aty43suulka2q4ybpaew4tey7rlw@l66rjb7vxxhk>
	<CAOYmi+=r50Kk1c7A7O8yXwJzALyyqDmQE7FiCZvZmt_3WRBGwQ@mail.gmail.com>
	<izopeja2suconbqpbswmtto5czajnc4p7rsml5gwwrs56lexaj@kmqdrqiepays>
	<rf5vuhdo4ub2qz3eivighhjs4tfkfclbosptnhzdpzibx5aq6z@faylol54ro5s>
	<slgx6krxgs2sb6m7j6z6qht25geaa2jbwwiizwimudrxqxxg3n@2qq5eslriowi>
	<tuobeew3dd3eubtelwroocwgac3jhlselwshs2km5ovei77tao@wghkpdvvthbi>
	<CAN4CZFMvnEPa2xpyvd7SYQ2U0os6gDucu_T_fsvM0q+xiqCD=w@mail.gmail.com>
	<uy2ho4qzwzsm5zqi2s3po4iesgvzfybdq6vldqpsldeot6xkyn@repwtjoc63ok>
	<a86c254e-834b-49e0-8ea1-f5ae58f61838@gmail.com>
	<aprTMCAqd16B__py@ddolgov-thinkpadt14sgen1.rmtde.csb>



On 9/4/26 7:35 AM, Dmitry Dolgov wrote:
>> On Mon, Aug 31, 2026 at 09:37:39AM -0700, Si, Evan wrote:
>>
>> Regardless, if RSA key exchange is used, SSL_get_negotiated_group is
>> supposed to return NID_undef. Things will error (Openssl 3.5 example):
> 
> Interesting, good to know, thanks. After a quick look I couldn't find
> any documentation as to why it's happening this way, I only see OpenSSL
> returning NID_undef if using tls1.2 and the ssl state has no session. Is
> there any explanation?


The documentation doesn't look terribly clear about this to me either, 
but I think its sensible. In the RSA case, there is no negotiation for 
the key, so getting undef out of "SSL_get_negotiated_group" sounds 
reasonable.

Poking around a bit more, there is some further nuance for non-EC DHE 
key exchange (e.g. ssl_ciphers=DHE-RSA-AES128-GCM-SHA256). The server 
always passes the FILE_DH2048 (or content of ssl_dh_params_file) into 
SSL_CTX_set_tmp_dh. This case would also mean there is no negotiation 
happening.

In TLSv1.3 there's no more support for custom dh though, so from my 
testing this SSL_CTX_set_tmp_dh is completely ignored there and things 
work fine (it has to all go through 
ssl_groups/SSL_CTX_set1_groups_list). In other words only for TLSv1.2 
and lower, non-EC DHE key exchange has no negotiation and thus NID_undef 
comes out of the API.

Evan






view thread (22+ messages)  latest in thread

Message-ID: <439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com>
Permalink:  ../439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com/
Also on:    postgresql.org/message-id/439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: evansi.dev@gmail.com, 9erthalion6@gmail.com, jacob.champion@enterprisedb.com, daniel@yesql.se, zsolt.parragi@percona.com
  Subject: Re: Add ssl_(supported|shared)_groups to sslinfo
  In-Reply-To: <439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox