Open MatteoGioioso opened 2 years ago
Thank you for reporting this issue.
The Docker image doesn't support root.crt
configuration. I think it cause this issue.
I am going to add ssl_ca_cert
support.
@pengbo0328 Thanks for your reply.
The Docker image doesn't support root.crt configuration
I though that was under pool.conf
, is there a build or startup option to allow it?
I am going to add ssl_ca_cert support.
That would be great, If you need help let me know. With some hints I could try to make a PR.
I though that was under pool.conf, is there a build or startup option to allow it?
I have updated the Docker image to allow the custom TLS certificates and private key: https://github.com/pgpool/pgpool2_on_k8s/blob/master/docs/index.md#tls-settings
However, sslrootcert
is not supported yet.
That would be great, If you need help let me know. With some hints I could try to make a PR.
It would be appreciated if you could make a PR.
@pengbo0328
As my understanding you are not adding the root.crt
into the pgpool.conf
from the entrypoint.sh
.
echo "ssl_ca_cert = '${PGPOOL_INSTALL_DIR}/tls/root.crt'" >> ${PGPOOL_INSTALL_DIR}/etc/pgpool.conf
Or is there something more that I am missing?
Thanks
@pengbo0328 I have added that line to the entrypoint.sh
and tested again and it worked.
I have made a PR
@pengbo0328 Hey, did you have time to take a look at the PR? Thanks
Hello
I am trying to setup TLS certificates with pgpool and postgres to have a secure connection between client <-> pgpool <-> postgres.
As my understanding when using
verify-ca
the client will provide the root certificate of the CA for verification with the backend; same should happen with pgpool in the middle, my client will provide the root certificate to verify the connection with pgpool, then pgpool will become the client and provide the root certificate viassl_ca_cert
option, to verify with the postgres backend.However pgpool seems to reject my ca, this is the link to the repro repository: https://github.com/MatteoGioioso/tls_issue_pgpool
Following those instructions, everything works by connecting directly to postgres:
Dockerfile:
This config will work with
verify-ca
:However same setup, but with pgpool (you can check it from the repo I have linked) it does not work:
In the logs: