-
+
This option controls how libpq verifies the certificate on the
server when performing an
SSL> connection. There are
three options: none> disables verification completely
- (not recommended!); cert> enables verification that
- the certificate chains to a known CA only; cn> will
- both verify that the certificate chains to a known CA and that
- the cn> attribute of the certificate matches the
- hostname the connection is being made to (default).
+ (not recommended); cert> enables verification that
+ the server certificate chains to a known certificate
+ authority (CA); cn> will both verify that the
+ certificate chains to a known CA and that the cn>
+ attribute of the server certificate matches the server's
+ hostname (default).