From 75ec5e7bec700577d39d653c316e3ae6c505842c Mon Sep 17 00:00:00 2001 From: Daniel Gustafsson Date: Thu, 20 Jul 2023 17:07:32 +0200 Subject: Add notBefore and notAfter to SSL cert info display This adds the X509 attributes notBefore and notAfter to sslinfo as well as pg_stat_ssl to allow verifying and identifying the validity period of the current client certificate. Author: Cary Huang Discussion: https://postgr.es/m/182b8565486.10af1a86f158715.2387262617218380588@highgo.ca --- src/backend/utils/activity/backend_status.c | 2 ++ 1 file changed, 2 insertions(+) (limited to 'src/backend/utils/activity/backend_status.c') diff --git a/src/backend/utils/activity/backend_status.c b/src/backend/utils/activity/backend_status.c index 38f91a495b8..02dc9d7931f 100644 --- a/src/backend/utils/activity/backend_status.c +++ b/src/backend/utils/activity/backend_status.c @@ -367,6 +367,8 @@ pgstat_bestart(void) be_tls_get_peer_subject_name(MyProcPort, lsslstatus.ssl_client_dn, NAMEDATALEN); be_tls_get_peer_serial(MyProcPort, lsslstatus.ssl_client_serial, NAMEDATALEN); be_tls_get_peer_issuer_name(MyProcPort, lsslstatus.ssl_issuer_dn, NAMEDATALEN); + be_tls_get_peer_not_before(MyProcPort, &lsslstatus.ssl_not_before); + be_tls_get_peer_not_after(MyProcPort, &lsslstatus.ssl_not_after); } else { -- cgit v1.2.3