diff options
author | Magnus Hagander <magnus@hagander.net> | 2019-03-09 12:09:10 -0800 |
---|---|---|
committer | Magnus Hagander <magnus@hagander.net> | 2019-03-09 12:19:47 -0800 |
commit | 0516c61b756e39ed6eb7a6bb54311a841002211a (patch) | |
tree | 7dc8f6760d2e0d1f19f1cbd5bde7cf09e0528ec0 /src/backend/access/gist/gist.c | |
parent | 6b9e875f7286d8535bff7955e5aa3602e188e436 (diff) | |
download | postgresql-0516c61b756e39ed6eb7a6bb54311a841002211a.tar.gz postgresql-0516c61b756e39ed6eb7a6bb54311a841002211a.zip |
Add new clientcert hba option verify-full
This allows a login to require both that the cn of the certificate
matches (like authentication type cert) *and* that another
authentication method (such as password or kerberos) succeeds as well.
The old value of clientcert=1 maps to the new clientcert=verify-ca,
clientcert=0 maps to the new clientcert=no-verify, and the new option
erify-full will add the validation of the CN.
Author: Julian Markwort, Marius Timmer
Reviewed by: Magnus Hagander, Thomas Munro
Diffstat (limited to 'src/backend/access/gist/gist.c')
0 files changed, 0 insertions, 0 deletions