sslmode does not support allow, prefer, require, disable
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 42/100
Direção de pesquisa
Localize a validação de sslmode e a configuração da conexão em redshift_connector e, em seguida, compare o comportamento atual com a documentação do PostgreSQL sobre sslmode e com a tabela de comportamentos desta issue. Adicione cobertura para os seis valores listados e verifique se cada modo produz o comportamento de conexão documentado.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Driver version
2.0.910
Redshift version
PostgreSQL 8.0.2 on i686-pc-linux-gnu, compiled by GCC gcc (GCC) 3.4.2 20041017 (Red Hat 3.4.2-6.fc3), Redshift 1.0.49780
Client Operating System
macos monterey 12.6.2
Python version
3.11
Table schema
Does not apply
Problem description
-
Expected behaviour:
In postgreSQL, these 5 parameters are allowed values for sslmode. However, redshift_connector only allows for verify-ca, and verify-full for this parameter. Redshift_connector also has ssl as a parameter. -
Actual behaviour:
There are a few problems with this difference between postgreSQL and redshift_connector:
a. To disable ssl, users using redshift_connector has to set ssl = False. Simply setting sslmode = disable will not set ssl to false. Since disable is not a recognizable value of sslmode in redshift_connector, redshift_connector will use the default of 'verify-ca' to make the connection.
b. According to the PostgreSQL doc, the accepted values of sslmode behave as below:
disable
only try a non-SSL connection
allow
first try a non-SSL connection; if that fails, try an SSL connection
prefer (default)
first try an SSL connection; if that fails, try a non-SSL connection
require
only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified
verify-ca
only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA)
verify-full
only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate
Redshift_connector should also increase the values accepted by sslmode to align with PostgreSQL docs
After some investigation, here is a detailed table on the behavior of sslmode of redshift_connector and psycopg2:
| sslmode | behavior in redshift connector (ssl, sslmode) | behavior in psycopg2 connector (sslmode) |
|---|---|---|
| disable | ssl=defaulted to true, sslmode=verify-ca (sslmode of disable is not recognized by redshift_connector, therefore falling back to default of verify-ca) | sslmode=disable |
| allow | ssl=defaulted to true, sslmode=verify-ca | first try with sslmode=disable, if fails, try with sslmode=verify-ca |
| prefer | ssl=defaulted to true, sslmode=verify-ca | first try with sslmode=verify-ca, if fails, try with sslmode=disable |
| require | ssl=defaulted to true, sslmode=verify-ca | ssl=true, sslmode=verify-ca |
| verify-ca | ssl=defaulted to true, sslmode=verify-ca | ssl=true, sslmode=verify-ca |
| verify-full | ssl=defaulted to true, sslmode=verify-full | ssl=true, sslmode=verify-full |
- Linguagem predominante
- Python
- Estrelas
- 220
- Forks
- 89
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de aws/amazon-redshift-python-driver
-
docs: client_protocol_version missing from Connection Parameters tableTalvez já em andamento @reginaldalfret assumiu há 8 dias. Aberta
Dificuldade 1/5 1-3 horas Facilidade para iniciantes 74/100
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 30/100
aws/amazon-redshift-python-driver#268 · 2 reações ·
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 35/100
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
aws/amazon-redshift-python-driver#265 · 1 comentário · 4 reações ·
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 45/100
Todas as issues de aws/amazon-redshift-python-driver
Issues semelhantes
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 60/100
521xueweihan/HelloGitHub#3924 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 67/100
wilbowes/EchoMuse#869 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 85/100
-
Claiming namespace `jft63`Abertanamespace operations
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
EclipseFdn/open-vsx.org#14043 ·
Mantenedores costumam responder em até 1 dia
-
test: TestServeUntilStale races the server's close against the client's sendall (BrokenPipeError under load)Talvez já em andamento @evoludigit assumiu hoje. Aberta
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 89/100
Mantenedores costumam responder em até 1 dia