pcp
[Top] [All Lists]

Re: pcp updates - overcome secure sockets breakage

To: "Frank Ch. Eigler" <fche@xxxxxxxxxx>
Subject: Re: pcp updates - overcome secure sockets breakage
From: Ken McDonell <kenj@xxxxxxxxxxxxxxxx>
Date: Wed, 24 Apr 2013 11:54:25 +1000
Cc: pcp@xxxxxxxxxxx
Delivered-to: pcp@xxxxxxxxxxx
In-reply-to: <20130423213600.GC20526@xxxxxxxxxx>
References: <51762D9B.3090702@xxxxxxxxxxxxxxxx> <y0mli89cqi3.fsf@xxxxxxxx> <5176F9A3.9040705@xxxxxxxxxxxxxxxx> <20130423213600.GC20526@xxxxxxxxxx>
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130329 Thunderbird/17.0.5
On 24/04/13 07:36, Frank Ch. Eigler wrote:
Hi -

kenj wrote:

[...]  And further I believe it is because our code is using the
sql: prefix

The idea would be drop all the sql: prefixes from our code, and
rely in the NSS environment variable to reactivate it for those
situations where the sysadmin/user prefers it.

That would work, but the default behaviour is different to what we have released in 3.7.1 (default == only option == sql:) ... my change removes hard-coded sql: references in the code, and preserves our current default (sql:) but allows the old style if required.

If we invert the default behaviour we risk messing up anyone who's already created and installed certificates for secure sockets (although I expect this may be a small, close to zero-sized, set of people).


when it tries to (again bogusly IMHO) load certificates even though
the client has no interest in secure sockets (and indeed there is no
certificate for pmcd in this installation).

(Yeah, I thought that bug was already understood and fixed or nearly fixed.)

I've not seen any code changes that would suggest this has been fixed, although I'd love to stand corrected.

<Prev in Thread] Current Thread [Next in Thread>