- url="https://tools.ietf.org/html/rfc6066#section-3">RFC 6066
- for details. By setting this parameter to 0, this is turned off.
+ Indication (
SNI) on SSL-enabled connections.
+ By setting this parameter to 0, this is turned off.
The Server Name Indication can be used by SSL-aware proxies to route
connections without having to decrypt the SSL stream. (Note that this
requires a proxy that is aware of the PostgreSQL protocol handshake,
- not just any SSL proxy.) However, SNI makes the destination host name
- appear in cleartext in the network traffic, so it might be undesirable
- in some cases.
+ not just any SSL proxy.) However,
SNI makes the
+ destination host name appear in cleartext in the network traffic, so
+ it might be undesirable in some cases.
-
Man in the middle (MITM)
+
Man-in-the-middle (MITM)
If a third party can modify the data while passing between the
client and server, it can pretend to be the server and therefore see and