Closed davecramer closed 6 months ago
@davecramer, @ongres, @ahachete: It is supported no?
Linked to:
@davecramer: Ping?
@Neustradamus this is more for @ahachete to implement
It is official, it is here: RFC 9266: Channel Bindings for TLS 1.3:
Dear @ongres team, @ahachete,
I think that you have seen the jabber.ru MITM and Channel Binding is the solution:
Linked to:
Getting the channel-binding data from an external security layer such as that provided by TLS is out of the scope for implementation in this library, TLS channel-binding data can be fetched using a library dedicated like the Bouncy Castle Crypto APIs.
Having said that, the channel binding type used by PostgreSQL is tls-server-end-point
, it could be fetched using Java's APIs without external libraries, and since this library was developed primarily to support SCRAM in PostgreSQL from Java, it could perfectly include a utility class to extract the cbind-data from the peer certificate.
This will be included in the next major release of the SCRAM library 3.0 which is being actively worked on, but there is no ETA for a final release yet.
@jorsol: It has been solved?
So what do we have to do with the JDBC driver to make this work. Just update the version ?
@jorsol: It has been solved?
For the PostgreSQL JDBC Driver use, yes.
So what do we have to do with the JDBC driver to make this work. Just update the version ?
https://github.com/pgjdbc/pgjdbc/pull/3188
Right now is in draft, maven central is having sync issues and the jars are not available yet. Also need to check what the pipeline has to say and fix it.
@jorsol: Good job about 3.0!
Important to specify in the ticket where it has been added.
PostgreSQL 11 will have channel binding. We'll need to extend the TLS interface to provide access to the Finished message and the peer certificate.