Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x2dD1-005sZt-0o for pgsql-hackers@arkaria.postgresql.org; Fri, 04 Sep 2026 23:20:35 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1x2dCz-009VMA-3B for pgsql-hackers@arkaria.postgresql.org; Fri, 04 Sep 2026 23:20:33 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x2dCz-009VM0-2B for pgsql-hackers@lists.postgresql.org; Fri, 04 Sep 2026 23:20:33 +0000 Received: from mail-yw1-x1135.google.com ([2607:f8b0:4864:20::1135]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1x2dCy-0000000435R-0OFe for pgsql-hackers@postgresql.org; Fri, 04 Sep 2026 23:20:32 +0000 Received: by mail-yw1-x1135.google.com with SMTP id 00721157ae682-86b03b75fecso27340417b3.0 for ; Fri, 04 Sep 2026 16:20:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788564030; x=1789168830; darn=postgresql.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Gdm8j85yQvL+Htl9f4vDvYTaumqB+7bgt8Zr83ckN2E=; b=LOp+I6TesotSxwPq9cCBIC00qjxD5S2dK3WNoxtCEvVkQNvLZ9oAGwyXz3+IxRkIUe 5c/xepupXcUSN0o+lfERV36WG0ULIsH2fagpZYEEvusKPBvMAZJ8LdtqC+1kMWf754IV 55qNLJ3x80F9DIckmPATHZhtuBwMUoSskTLifkpfJ6w9ZPDCQL/VW4ve62cjfp6X6IaG oH/FifzHm2MalkcwC64B6w1WbTyacyBE//aCmtzxQoRAFhRGIG1npJdoNLA3UGZ++DNd fwIuBAuwvV3cIOiOIllfRhXpVHbxJhZobd6BoeEhw+99TtsPmMcX2QPDuTO4ZFzoKbF8 Xk2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788564030; x=1789168830; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Gdm8j85yQvL+Htl9f4vDvYTaumqB+7bgt8Zr83ckN2E=; b=AxK4h2lEssDuHSgGNnt2Gghu/XHlwDyV6EWzfOFiqCk6zzRcTBm2Hwfpom5wDBEgGf PsCImNr+KU8iLIwqFHOdTrCoANhtMPsVM/lhTcCl/mUe9y118D4Z69aCzD0nuZ9RlNAx TNPCe1qNNJlZBkbRaFWEiyWvfjgcs9nLawgsFtcx8JkCoYldc7LiyerhsMuVYVhZ8cSD O53t8m9vUSWh9n5+LEHvBbBElI9uzQHMLVPx5PUT2DuPIHubnGpc9AzGbPM4yamfc6US GKX8hq2V4V379H4dbN/X+ZZZpTXXH8lhC+ec2XFPMZp9UDbCOrTgmIPsdVvyCUtRZ3Y3 Ga0w== X-Forwarded-Encrypted: i=1; AKwUvBx6etmhqep1HA2nUbtvBONihop9+djrcoRZ3Q+Na3QK2COVHZjB9pHJpd8Se5GXit/x4QMIUf07LiYmdONz@postgresql.org X-Gm-Message-State: AFuF++lsBi/TvQsNmsNFPA4firZpobBGhd2qld0yJjJ221958FGLqJb0 MgoO4kP8B+BsYnis/perCwRDJJZAQ+u3w2L6difMTLLbLbpPDAm41nxW X-Gm-Gg: AYBFou2Q5vpYMc7z/Nb2dwEe9UTzOCAwdNK0tvKIIOUJjLmEFtxeB2It+5EjrDteSiI w+C0UhIGkIyNEdB0//c+sVAETVl/bTII+vpTgj+WJfBs/Z63SVW1OGOVR2mUeo2QKh//sfkPjUH 6v4qiuOihFFaz5rlq9lNB1oy1sIagN0LfqsGVYxy0fKQF0dEJ4O7Prc5CP8s84nQOWaXzX/rRqH FjhOQmi05TnPdentGbthX7MXIyoqG/x/DUy722C+YG2/5GO6Sk6Xb05VXaZtI4abvKBa2G0WjV4 L/GcPXfVudR7Fuvb86/dzTCogIjOYd2CGXyS3QMPXvKFrnidUyXhDqVsaP5yIVKBdo8KzFaBBeT reIPZXIjodY4z2qD/mXnuPeF8wBVbC1kr/33VMkLih+RquHh1ae/fKmx5AEGz6gBn1LTt7CFd82 KmxcpzhhrqatdzWCi4wEG1eu23aoR31vxUUFW/NlZRMlOD9Rzh0nPunh8N+7z9/RJdRE4DqyFjA XedVXH+j1rrIazgYzYChesBDse61HnjbyT8fTwxdCU53tIImxfIZpc/9jfHww== X-Received: by 2002:a05:690c:4ad9:b0:7bd:cf35:e33b with SMTP id 00721157ae682-87125ff0332mr40106687b3.17.1788564029889; Fri, 04 Sep 2026 16:20:29 -0700 (PDT) Received: from ?IPV6:2600:1702:1d00:bf10:b06f:a9ea:f789:13cf? ([2600:1702:1d00:bf10:b06f:a9ea:f789:13cf]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8713d68fd00sm30055047b3.0.2026.09.04.16.20.28 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 04 Sep 2026 16:20:29 -0700 (PDT) Message-ID: <439f9b38-c610-48e0-ae1d-798a58dc2cc8@gmail.com> Date: Fri, 4 Sep 2026 16:20:27 -0700 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Add ssl_(supported|shared)_groups to sslinfo To: Dmitry Dolgov <9erthalion6@gmail.com> Cc: Jacob Champion , Daniel Gustafsson , PostgreSQL Hackers , Zsolt Parragi References: Content-Language: en-US From: "Si, Evan" In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On 9/4/26 7:35 AM, Dmitry Dolgov wrote: >> On Mon, Aug 31, 2026 at 09:37:39AM -0700, Si, Evan wrote: >> >> Regardless, if RSA key exchange is used, SSL_get_negotiated_group is >> supposed to return NID_undef. Things will error (Openssl 3.5 example): > > Interesting, good to know, thanks. After a quick look I couldn't find > any documentation as to why it's happening this way, I only see OpenSSL > returning NID_undef if using tls1.2 and the ssl state has no session. Is > there any explanation? The documentation doesn't look terribly clear about this to me either, but I think its sensible. In the RSA case, there is no negotiation for the key, so getting undef out of "SSL_get_negotiated_group" sounds reasonable. Poking around a bit more, there is some further nuance for non-EC DHE key exchange (e.g. ssl_ciphers=DHE-RSA-AES128-GCM-SHA256). The server always passes the FILE_DH2048 (or content of ssl_dh_params_file) into SSL_CTX_set_tmp_dh. This case would also mean there is no negotiation happening. In TLSv1.3 there's no more support for custom dh though, so from my testing this SSL_CTX_set_tmp_dh is completely ignored there and things work fine (it has to all go through ssl_groups/SSL_CTX_set1_groups_list). In other words only for TLSv1.2 and lower, non-EC DHE key exchange has no negotiation and thus NID_undef comes out of the API. Evan