Unable to use `pgcli service={service}`
维护者通常 2 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 52/100
调研方向
首先,使用 .pg_service.conf 中的条目以及 postgresql.conf 和 pg_hba.conf 中的 PostgreSQL 连接设置,将 pgcli service={service} 的处理与正常工作的 PostgreSQL URI 命令进行比较。使用列出的命令重现故障,并验证基于 service 的连接使用与 URI 形式相同的客户端证书、密钥、CA 和 SSL 设置。
由索引模型根据 Issue 内容生成。
描述
Description
I am running a PostgreSQL server in a Docker container and using Secure TCP/IP Connections with SSL.
In my postgresql.conf file, I include the following lines:
ssl = on
ssl_ca_file = '/run/secrets/ca.crt'
ssl_cert_file = '/run/secrets/server.crt'
ssl_key_file = '/run/secrets/server.key'
# This setting is on by default but it’s always a good idea to
# be explicit when it comes to security.
ssl_prefer_server_ciphers = on
# TLS 1.3 will give the strongest security and is advised when
# controlling both server and clients.
ssl_min_protocol_version = 'TLSv1.3'
I have a .pg_service.conf file where I define a service named {service}:
[{service}]
host={host}
port={port}
user={user}
dbname={dbname}
sslmode=verify-full
sslrootcert=/path/to/ca.crt
sslcert=/path/to/user.crt
sslkey=/path/to/user.key
The command psql service={service} prompts for the password of the user included in the service definition and successfully connects to the specified database afterwards.
However, the command pgcli service={service} returns the following error message:
connection failed: FATAL: connection requires a valid client certificate
connection to server at "{host}", port {port} failed: FATAL: no pg_hba.conf entry for host "{host}", user "{user}", database "{dbname}", no encryption
In the PostgreSQL server logs I see the following entries:
postgres | 2024-08-06 10:50:35.387 GMT [117]: [1-1] user={user},db={dbname} FATAL: connection requires a valid client certificate
postgres | 2024-08-06 10:50:35.390 GMT [118]: [1-1] user={user},db={dbname} FATAL: no pg_hba.conf entry for host "{host}", user "{user}", database "{dbname}", no encryption
Note that the pg_hba.conf I am using contains the following line:
hostssl {dbname} {user} {host}/32 scram-sha-256 clientcert=verify-full
Surprisingly, the command pgcli "postgresql://{user}@{host}/{dbname}?port={port}&sslmode=verify-full&sslkey=/path/to/user.key&sslcert=/path/to/user.crt&sslrootcert=/path/to/ca.crt" successfully connects to the specified database after prompting for the user password. Same thing happens if I replace pgcli with psql.
Note that in the .pg_service.conf file I am using the very same paths to the user.key, user.crt, and ca.crt files.
Your environment
- Debian 12 (bookworm)
- pgcli 4.1.0 - python 3.12.4 (installed with conda/mamba).
- Packages included in my conda/mamba env include, among other packages:
- ca-certificates 2024.7.4-hbcca054_0
- certifi 2024.7.4-pyhd8ed1ab_0
- openssl 3.3.1-h4bc722e_2
- postgresql 16.3-h8e811e2_0
- 主要语言
- Python
- 星标
- 13.4k
- 派生
- 612
- 平均合并
- 15 小时 57 分钟
- 30 天内合并 PR
- 4
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
dbcli/pgcli 的其他 Issue
-
难度 3/5 1-2 天 新手友好度 64/100
维护者通常 2 天内回复
-
难度 5/5 一周以上 新手友好度 35/100
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 72/100
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 68/100
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
维护者通常 2 天内回复
相似的 Issue
-
enhancement P2
难度 2/5 1-3 小时 新手友好度 78/100
Toloka/tolokaforge#1776 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
TencentCloud/Octop#1622 ·
维护者通常 1 天内回复
-
Independent PhaseMap objects share and leak their default mode grouping可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 68/100
-
Rust: `const _` gets its file's node ID, so the file node is relabelled `_` and gains a self-loop未关闭
难度 2/5 1-3 小时 新手友好度 78/100
Graphify-Labs/graphify#4064 · 1 条评论 ·
维护者通常 2 天内回复