0b5d1fb36a
The error message for a missing or invalid system CA when using sslrootcert=system differs based on the OpenSSL version used. In OpenSSL 1.0.1-3.0 it is reported as SSL Error, with varying degrees of helpfulness in the error message. With OpenSSL 3.1 it is reported as an SSL SYSCALL error with "Undefined error" as the error message. This fix pulls out the particular error in OpenSSL 3.1 as a certificate verify error in order to help the user better figure out what happened, and to keep the ssl test working. While there is no evidence that extracing the errors will clobber errno, this adds a guard against that regardless to also make the consistent with how we handle OpenSSL errors elsewhere. It also memorizes the output from OpenSSL 3.0 in the test in cases where the system CA isn't responding. Reported-by: Peter Eisentraut <peter.eisentraut@enterprisedb.com> Discussion: https://postgr.es/m/c39be3c5-c1a5-1e33-1024-16f527e251a4@enterprisedb.com |
||
---|---|---|
.. | ||
po | ||
t | ||
test | ||
.gitignore | ||
Makefile | ||
README | ||
exports.txt | ||
fe-auth-sasl.h | ||
fe-auth-scram.c | ||
fe-auth.c | ||
fe-auth.h | ||
fe-connect.c | ||
fe-exec.c | ||
fe-gssapi-common.c | ||
fe-gssapi-common.h | ||
fe-lobj.c | ||
fe-misc.c | ||
fe-print.c | ||
fe-protocol3.c | ||
fe-secure-common.c | ||
fe-secure-common.h | ||
fe-secure-gssapi.c | ||
fe-secure-openssl.c | ||
fe-secure.c | ||
fe-trace.c | ||
legacy-pqsignal.c | ||
libpq-events.c | ||
libpq-events.h | ||
libpq-fe.h | ||
libpq-int.h | ||
meson.build | ||
nls.mk | ||
pg_service.conf.sample | ||
pqexpbuffer.c | ||
pqexpbuffer.h | ||
pthread-win32.c | ||
win32.c | ||
win32.h |
README
src/interfaces/libpq/README This directory contains the C version of Libpq, the POSTGRES frontend library.