From: Francis Dupont Date: Wed, 9 Jul 2025 13:52:51 +0000 (+0200) Subject: [#3927] Updated the default to library one 2 X-Git-Tag: Kea-3.1.0~44 X-Git-Url: http://git.ipfire.org/gitweb/gitweb.cgi?a=commitdiff_plain;h=e7cab5f3c82278f82be9dc9893dfc41fcbf511fa;p=thirdparty%2Fkea.git [#3927] Updated the default to library one 2 --- diff --git a/src/lib/pgsql/pgsql_connection.cc b/src/lib/pgsql/pgsql_connection.cc index 3c3e8949f7..7cb17dac0f 100644 --- a/src/lib/pgsql/pgsql_connection.cc +++ b/src/lib/pgsql/pgsql_connection.cc @@ -411,9 +411,9 @@ PgSqlConnection::getConnParametersInternal(bool logging) { bool tls = false; - string ssslmode; + string sslmode; try { - ssslmode = getParameter("ssl-mode"); + sslmode = getParameter("ssl-mode"); tls = true; } catch (...) { // No strict ssl mode @@ -423,8 +423,8 @@ PgSqlConnection::getConnParametersInternal(bool logging) { try { sca = getParameter("trust-anchor"); tls = true; - if (ssslmode.empty()) { - ssslmode = "verify-ca"; + if (sslmode.empty()) { + sslmode = "verify-ca"; } dbconnparameters += " sslrootcert = " + sca; } catch (...) { @@ -450,17 +450,17 @@ PgSqlConnection::getConnParametersInternal(bool logging) { } if (tls) { - if (ssslmode.empty()) { - ssslmode = "require"; + if (sslmode.empty()) { + sslmode = "require"; } dbconnparameters += " gssencmode = disable"; } else { - if (ssslmode.empty()) { - ssslmode = "disable"; + if (sslmode.empty()) { + sslmode = "prefer"; } } - dbconnparameters += " sslmode = " + ssslmode; + dbconnparameters += " sslmode = " + sslmode; return (dbconnparameters); }