]> git.ipfire.org Git - thirdparty/postgresql.git/commitdiff
Fix pg_hba_file_rules for authentication method cert
authorMagnus Hagander <magnus@hagander.net>
Wed, 26 Jan 2022 08:52:41 +0000 (09:52 +0100)
committerMagnus Hagander <magnus@hagander.net>
Wed, 26 Jan 2022 08:59:14 +0000 (09:59 +0100)
For authentication method cert, clientcert=verify-full is implied. But
the pg_hba_file_rules entry would incorrectly show clientcert=verify-ca.

Per bug #17354

Reported-By: Feike Steenbergen
Reviewed-By: Jonathan Katz
Backpatch-through: 12

src/backend/libpq/hba.c

index 3be8778d21668ae2321cac94390cdbeb1bb18641..64e59d4d88a4488be8174b15cf802729049b04e0 100644 (file)
@@ -1684,7 +1684,11 @@ parse_hba_line(TokenizedLine *tok_line, int elevel)
         */
        if (parsedline->auth_method == uaCert)
        {
-               parsedline->clientcert = clientCertCA;
+               /*
+                * For auth method cert, client certificate validation is mandatory, and it implies
+                * the level of verify-full.
+                */
+               parsedline->clientcert = clientCertFull;
        }
 
        return parsedline;