Skip to content

Commit b1ae70b

Browse files
committed
docs: clarify intermediate certificate creation instructions
Specifically, explain the v3_ca openssl specification. Discussion: https://postgr.es/m/20200824175653.GA32411@momjian.us Backpatch-through: 9.5
1 parent 70e791f commit b1ae70b

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

doc/src/sgml/runtime.sgml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2193,8 +2193,10 @@ pg_dumpall -p 5432 | psql -d postgres -p 5433
21932193
The certificates of <quote>intermediate</quote> certificate authorities
21942194
can also be appended to the file. Doing this avoids the necessity of
21952195
storing intermediate certificates on clients, assuming the root and
2196-
intermediate certificates were created with <literal>v3_ca</literal>
2197-
extensions. This allows easier expiration of intermediate certificates.
2196+
intermediate certificates were created with <literal>v3_ca </literal>
2197+
extensions. (This sets the certificate's basic constraint of
2198+
<literal>CA</literal> to <literal>true</literal>.)
2199+
This allows easier expiration of intermediate certificates.
21982200
</para>
21992201

22002202
<para>

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy