ssl_renegotiation_limit
Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.
英文手册覆盖始于 PostgreSQL 7.4. 来源历史与运行验证各自保留独立版本边界。
当前阅读 PG 9.4·选择有来源记录的版本
此版本暂无所选语言的定义,以下显示原始英文内容。
- boot val
- 0
- category
- Connections and Authentication / Security and Authentication
- context
- user
- documented
- true
- enumvals
- 未知
- extra desc
- 未知
- lang
- en
- max val
- 2147483647
- metadata version
- 9.4
- min val
- 0
- name
- ssl_renegotiation_limit
- short desc
- Set the amount of traffic to send and receive before renegotiating the encryption keys.
- source
- pg-settings-source-snapshot
- unit
- kB
- vartype
- integer
版本定义 PG 9.4
Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.
比较版本
来源引用
定义来源
center · PostgreSQL 9.4 · english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe
正文语言: en · english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe