Add verified PostgreSQL TLS mode - #94
Conversation
|
Warning Review limit reachedNext included review available in 27 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (12)
Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Summary
LEGACY,DISABLE,REQUIRE, andVERIFY_FULLUseSSLbehavior as the default for upgrade compatibilityVERIFY_FULLrequest CA and hostname verification, while documenting thatREQUIREprovides encryption without server identity verificationSecurity model and compatibility
LEGACYis the default and preserves existing installations, including private or self-signed deployments. Operators can migrate explicitly toVERIFY_FULLafter installing a trusted CA and using a hostname that matches the server certificate. Explicit PostgreSQL modes also disable GSS encryption negotiation so the chosen SSL mode remains authoritative. MySQL and MariaDB behavior is unchanged, and PostgreSQL-only modes are rejected for those drivers.Validation
mvn -B -f SimpleAPI/pom.xml clean packagepassed: 413 tests, no failures/errorsgit diff --checkpassed