Closed nicksrandall closed 10 months ago
This new config option in Postgres v16 can help prevent MITM attacks. It would be great if this was supported in postgres.js.
More info: https://neon.tech/blog/avoid-mitm-attacks-with-psql-postgres-16
Basically, ?sslrootcert=system is a shortened way to say ?sslmode=verify-full&sslrootcert=/etc/ssl/cert.pem
?sslrootcert=system
?sslmode=verify-full&sslrootcert=/etc/ssl/cert.pem
Hi @nicksrandall - yeah that's cool! I'm open for a PR, if you don't want to wait until I need it myself 😉
@porsager PR is here: #690
Haha - oh my - it was right there 😍 sorry - tired eyes
Fixed in #690
This new config option in Postgres v16 can help prevent MITM attacks. It would be great if this was supported in postgres.js.
More info: https://neon.tech/blog/avoid-mitm-attacks-with-psql-postgres-16
Basically,
?sslrootcert=system
is a shortened way to say?sslmode=verify-full&sslrootcert=/etc/ssl/cert.pem