aboutsummaryrefslogtreecommitdiff
path: root/src/backend/utils/misc/postgresql.conf.sample
diff options
context:
space:
mode:
authorPeter Eisentraut <peter_e@gmx.net>2012-02-22 23:40:46 +0200
committerPeter Eisentraut <peter_e@gmx.net>2012-02-22 23:40:46 +0200
commita445cb92ef5b3a31313ebce30e18cc1d6e0bdecb (patch)
treed760ab6cc486f2d052e7ff1e728c28f24d025d2e /src/backend/utils/misc/postgresql.conf.sample
parenta417f85e1da1ef241af4bf40507ca213464d7069 (diff)
downloadpostgresql-a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb.tar.gz
postgresql-a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb.zip
Add parameters for controlling locations of server-side SSL files
This allows changing the location of the files that were previously hard-coded to server.crt, server.key, root.crt, root.crl. server.crt and server.key continue to be the default settings and are thus required to be present by default if SSL is enabled. But the settings for the server-side CA and CRL are now empty by default, and if they are set, the files are required to be present. This replaces the previous behavior of ignoring the functionality if the files were not found.
Diffstat (limited to 'src/backend/utils/misc/postgresql.conf.sample')
-rw-r--r--src/backend/utils/misc/postgresql.conf.sample4
1 files changed, 4 insertions, 0 deletions
diff --git a/src/backend/utils/misc/postgresql.conf.sample b/src/backend/utils/misc/postgresql.conf.sample
index 400c52bf9d7..96da086b0f4 100644
--- a/src/backend/utils/misc/postgresql.conf.sample
+++ b/src/backend/utils/misc/postgresql.conf.sample
@@ -81,6 +81,10 @@
#ssl_ciphers = 'ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH' # allowed SSL ciphers
# (change requires restart)
#ssl_renegotiation_limit = 512MB # amount of data between renegotiations
+#ssl_cert_file = 'server.crt' # (change requires restart)
+#ssl_key_file = 'server.key' # (change requires restart)
+#ssl_ca_file = '' # (change requires restart)
+#ssl_crl_file = '' # (change requires restart)
#password_encryption = on
#db_user_namespace = off