Re: [GENERAL] stunnel with just postgresql client part

2011-05-10 Thread Merlin Moncure
On Tue, May 10, 2011 at 6:09 AM, zhong ming wu wrote: > On Mon, May 9, 2011 at 10:50 PM, Merlin Moncure wrote: > >> Now manybe *I'm* a little confused.  Are you connecting to the write >> port (stunnel's secure port)? As I understand it, the stunnel pgsql >> protocol is such that the client side

Re: [GENERAL] stunnel with just postgresql client part

2011-05-10 Thread zhong ming wu
On Mon, May 9, 2011 at 10:50 PM, Merlin Moncure wrote: > Now manybe *I'm* a little confused.  Are you connecting to the write > port (stunnel's secure port)? As I understand it, the stunnel pgsql > protocol is such that the client side libpq application can connect to > stunnel which unwraps the

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread Merlin Moncure
On Mon, May 9, 2011 at 7:17 PM, zhong ming wu wrote: > On Mon, May 9, 2011 at 6:42 PM, Merlin Moncure wrote: >>> Thanks.  Yes, when I installed the latest stunnel-4.36 it works. >>> >>> One strange thing I notice.  When I do ssl connect with psql I am >>> supposed to get a message like >>> >>> SS

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread zhong ming wu
On Mon, May 9, 2011 at 6:42 PM, Merlin Moncure wrote: >> Thanks.  Yes, when I installed the latest stunnel-4.36 it works. >> >> One strange thing I notice.  When I do ssl connect with psql I am >> supposed to get a message like >> >> SSL connection (cipher: DHE-RSA-AES256-SHA, bits: 256) >> >> Wit

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread Merlin Moncure
On Mon, May 9, 2011 at 5:03 PM, zhong ming wu wrote: > On Mon, May 9, 2011 at 4:37 PM, Merlin Moncure wrote: >>> I was not setting protocol.  But since I got your message, I tried >>> 'protocol = pgsql' in stunnel.conf >> >> see: >> http://pgbouncer.projects.postgresql.org/doc/faq.html#_how_to_u

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread zhong ming wu
On Mon, May 9, 2011 at 4:37 PM, Merlin Moncure wrote: >> I was not setting protocol.  But since I got your message, I tried >> 'protocol = pgsql' in stunnel.conf > > see: > http://pgbouncer.projects.postgresql.org/doc/faq.html#_how_to_use_ssl_connections_with_pgbouncer > > "Use Stunnel. Since ver

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread Merlin Moncure
On Mon, May 9, 2011 at 3:24 PM, zhong ming wu wrote: > On Mon, May 9, 2011 at 2:01 PM, Merlin Moncure wrote: > . > . > . >>>  It seems to be shame that I have to run stunnel on the pg box as well. >>> >>> My question is that client only stunnel to pg server requiring ssl >>> connection is not exp

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread zhong ming wu
On Mon, May 9, 2011 at 2:01 PM, Merlin Moncure wrote: . . . >>  It seems to be shame that I have to run stunnel on the pg box as well. >> >> My question is that client only stunnel to pg server requiring ssl >> connection is not expected to work?  Or am I doing something wrong? > > what version st

Re: [GENERAL] stunnel with just postgresql client part

2011-05-09 Thread Merlin Moncure
On Mon, May 9, 2011 at 9:35 AM, zhong ming wu wrote: > Hi > > My postgresql client (ejabberd postgresql lib) does not seem to be > capable of ssl connection to postgresql server (with hostssl in > pg_hba) > > So I tried to use run stunnel on the client box (ejabberd).  It > appears not to work. >

[GENERAL] stunnel with just postgresql client part

2011-05-09 Thread zhong ming wu
Hi My postgresql client (ejabberd postgresql lib) does not seem to be capable of ssl connection to postgresql server (with hostssl in pg_hba) So I tried to use run stunnel on the client box (ejabberd). It appears not to work. Here is stunnel log on the client end -- 2011.05.09 0