From 38ade59f95bcd446225c8eda94db52c190311a1f Mon Sep 17 00:00:00 2001 From: Bruce Momjian <bruce@momjian.us> Date: Thu, 6 Mar 2008 21:25:50 +0000 Subject: [PATCH] Add: > > * Allow client certificate names to be checked against the client > hostname > > This is already implemented in > libpq/fe-secure.c::verify_peer_name_matches_certificate() but the code > is commented out. --- doc/TODO | 9 ++++++++- doc/src/FAQ/TODO.html | 8 +++++++- 2 files changed, 15 insertions(+), 2 deletions(-) diff --git a/doc/TODO b/doc/TODO index cca5e1a1191..5f95888bfbb 100644 --- a/doc/TODO +++ b/doc/TODO @@ -1,7 +1,7 @@ PostgreSQL TODO List ==================== Current maintainer: Bruce Momjian (bruce@momjian.us) -Last updated: Thu Mar 6 13:00:54 EST 2008 +Last updated: Thu Mar 6 16:25:41 EST 2008 The most recent version of this document can be viewed at http://www.postgresql.org/docs/faqs.TODO.html. @@ -85,6 +85,13 @@ Administration http://archives.postgresql.org/pgsql-hackers/2007-12/msg00924.php +* Allow client certificate names to be checked against the client + hostname + + This is already implemented in + libpq/fe-secure.c::verify_peer_name_matches_certificate() but the code + is commented out. + * Configuration files o Allow pg_hba.conf to specify host names along with IP addresses diff --git a/doc/src/FAQ/TODO.html b/doc/src/FAQ/TODO.html index bda4e8b5585..81c8889ae14 100644 --- a/doc/src/FAQ/TODO.html +++ b/doc/src/FAQ/TODO.html @@ -8,7 +8,7 @@ <body bgcolor="#FFFFFF" text="#000000" link="#FF0000" vlink="#A00000" alink="#0000FF"> <h1><a name="section_1">PostgreSQL TODO List</a></h1> <p>Current maintainer: Bruce Momjian (<a href="mailto:bruce@momjian.us">bruce@momjian.us</a>)<br/> -Last updated: Thu Mar 6 13:00:54 EST 2008 +Last updated: Thu Mar 6 16:25:41 EST 2008 </p> <p>The most recent version of this document can be viewed at<br/> <a href="http://www.postgresql.org/docs/faqs.TODO.html">http://www.postgresql.org/docs/faqs.TODO.html</a>. @@ -81,6 +81,12 @@ first. There is also a developer's wiki at<br/> </p> </li><li>Allow SSL authentication/encryption over unix domain sockets <p> <a href="http://archives.postgresql.org/pgsql-hackers/2007-12/msg00924.php">http://archives.postgresql.org/pgsql-hackers/2007-12/msg00924.php</a> +</p> + </li><li>Allow client certificate names to be checked against the client + hostname +<p> This is already implemented in + libpq/fe-secure.c::verify_peer_name_matches_certificate() but the code + is commented out. </p> </li><li>Configuration files <ul> -- GitLab