Skip to content

Support inline SSL certificates - #818

Merged
madelynnblue merged 3 commits into
lib:masterfrom
eirslett:feature/ssl-inline
Feb 12, 2021
Merged

Support inline SSL certificates#818
madelynnblue merged 3 commits into
lib:masterfrom
eirslett:feature/ssl-inline

Conversation

@eirslett

Copy link
Copy Markdown
Contributor

Presently, pq only supports SSL connections by
loading PEM certificates from files on disk.
There are some situations (for example integration
with HashiCorp Vault) where it's not so feasible
to load certificates from a file system, but better
to store them in-memory.

This patch lets you set ?sslinline=true in the
connection string, which changes the behavior of
the paramters sslrootcert, sslcert and sslkey, so
they contain the contents of the certificates
directly, instead of file names pointing to the
certificates on disk.

What do you think about a change like this?
My specific use case is adding SSL support to Vault's integration with PostgreSQL - today it can only communicate over a plaintext socket. However, Vault doesn't store secrets/certificates directly on disk, but rather on an encrypted, distributed, pluggable backend system, which is the reason for this feature request: Vault can read the certificates from wherever they are stored, and pass them into pq via the connection string.

Comment thread url.go
accrue := func(k, v string) {
if v != "" {
kvs = append(kvs, k+"="+escaper.Replace(v))
kvs = append(kvs, k+"='"+escaper.Replace(v)+"'")

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change was made because PEM certificates include newlines, equal signs and various stuff that is tricky to escape - but by adding single quotes, we can work around the problem.

@eirslett

Copy link
Copy Markdown
Contributor Author

I'm not sure why the Travis build fails... looks like a flaky test, maybe? Could somebody please trigger a new build?

@umran

umran commented Jan 3, 2020

Copy link
Copy Markdown

I have the exact same use case, which is what led me to this PR and the PR you submitted to Vault: hashicorp/vault#5963. I really hope this gets reviewed at some point.

@binlab

binlab commented Feb 11, 2021

Copy link
Copy Markdown

@mjibson could you please look at this PR? Would be nice to have the possibility to use inline certificates. Hope for your help, thanks!

@madelynnblue

Copy link
Copy Markdown
Collaborator

Can you or someone rebase this on master so the tests re-run? Open a new PR and mention me if needed.

Presently, pq only supports SSL connections by
loading PEM certificates from files on disk.
There are some situations (for example integration
with HashiCorp Vault) where it's not so feasible
to load certificates from a file system, but better
to store them in-memory.

This patch lets you set ?sslinline=true in the
connection string, which changes the behavior of
the paramters sslrootcert, sslcert and sslkey, so
they contain the contents of the certificates
directly, instead of file names pointing to the
certificates on disk.
@eirslett

Copy link
Copy Markdown
Contributor Author

2 years already... time flies! I rebased it on top of master now. 🤞

@madelynnblue
madelynnblue merged commit 072e83d into lib:master Feb 12, 2021
@eirslett
eirslett deleted the feature/ssl-inline branch February 14, 2021 16:37
@binlab

binlab commented Feb 15, 2021

Copy link
Copy Markdown

@mjibson @eirslett thanks for making it possible!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants