Re: TLS 1.0

2021-08-06 Thread Steve Crawford
>From a security audit point of view, also consider the fact that 9.6 is end-of-life in 3 months. -Steve On Fri, Aug 6, 2021 at 9:46 AM Tom Lane wrote: > Ehtesham Pradhan writes: > > Our client is using Version : PostgreSQL 9.6.17 , they have done > vulnerability > > assessment and found that

Re: TLS 1.0

2021-08-06 Thread Tom Lane
Ehtesham Pradhan writes: > Our client is using Version : PostgreSQL 9.6.17 , they have done > vulnerability > assessment and found that : >- TLS version 1.0 Protocol detection >- The remote service encrypt traffic with older version of TLS This is mostly a matter of whether the OpenSSL

TLS 1.0

2021-08-06 Thread Ehtesham Pradhan
Hi Team, Our client is using Version : PostgreSQL 9.6.17 , they have done vulnerability assessment and found that : - TLS version 1.0 Protocol detection - The remote service encrypt traffic with older version of TLS We suggested the below changes in PostgresSQL.conf ssl_ciphers = 'HIGH: