</para>
<sect2 id="libq-ssl-certificates">
- <title>Certificate verification</title>
+ <title>Client Verification of Server Certificates</title>
<para>
By default, <productname>PostgreSQL</> will not perform any verification of
</sect2>
<sect2 id="libpq-ssl-clientcert">
- <title>Client certificates</title>
+ <title>Client Certificates</title>
<para>
If the server requests a trusted client certificate,
</sect2>
<sect2 id="libpq-ssl-protection">
- <title>Protection provided in different modes</title>
+ <title>Protection Provided in Different Modes</title>
<para>
The different values for the <literal>sslmode</> parameter provide different
protection against three types of attacks:
</para>
<table id="libpq-ssl-protect-attacks">
- <title>SSL attacks</title>
+ <title>SSL Attacks</title>
<tgroup cols="2">
<thead>
<row>
</para>
<table id="libpq-ssl-sslmode-statements">
- <title>SSL mode descriptions</title>
+ <title>SSL Mode Descriptions</title>
<tgroup cols="4">
<thead>
<row>
</sect2>
<sect2 id="libpq-ssl-fileusage">
- <title>SSL File Usage</title>
+ <title>SSL Client File Usage</title>
<table id="libpq-ssl-file-usage">
<title>Libpq/Client SSL File Usage</title>
<tgroup cols="3">
</sect2>
<sect2 id="libpq-ssl-initialize">
- <title>SSL library initialization</title>
+ <title>SSL Library Initialization</title>
<para>
If your application initializes <literal>libssl</> and/or
<tbody>
<row>
- <entry><filename>server.crt</></entry>
+ <entry><filename>$PGDATA/server.crt</></entry>
<entry>server certificate</entry>
<entry>sent to client to indicate server's identity</entry>
</row>
<row>
- <entry><filename>server.key</></entry>
+ <entry><filename>$PGDATA/server.key</></entry>
<entry>server private key</entry>
<entry>proves server certificate was sent by the owner; does not indicate
certificate owner is trustworthy</entry>
</row>
<row>
- <entry><filename>root.crt</></entry>
+ <entry><filename>$PGDATA/root.crt</></entry>
<entry>trusted certificate authorities</entry>
<entry>checks that client certificate is
signed by a trusted certificate authority</entry>
</row>
<row>
- <entry><filename>root.crl</></entry>
+ <entry><filename>$PGDATA/root.crl</></entry>
<entry>certificates revoked by certificate authorities</entry>
<entry>client certificate must not be on this list</entry>
</row>