↑↓ 选择↵ 打开⌫ 切换范围完整搜索

PG.CENTER 连接 PostgreSQL 文档、百科与生态知识。由 Pigsty 维护。

Wiki / 配置参数

ssl_renegotiation_limit

Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.

英文手册覆盖始于 PostgreSQL 7.4. 来源历史与运行验证各自保留独立版本边界。

当前阅读 PG 9.4·选择有来源记录的版本

此版本暂无所选语言的定义,以下显示原始英文内容。

boot val
0
category
Connections and Authentication / Security and Authentication
context
user
documented
true
enumvals
未知
extra desc
未知
lang
en
max val
2147483647
metadata version
9.4
min val
0
name
ssl_renegotiation_limit
short desc
Set the amount of traffic to send and receive before renegotiating the encryption keys.
source
pg-settings-source-snapshot
unit
kB
vartype
integer

版本定义 PG 9.4

Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.

比较版本

来源引用

完整定义与证据 JSON

定义来源

center · PostgreSQL 9.4 · english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe

正文语言: en · english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe