Merge pull request #247 from erickedji/patch-1

Extend server certificate validity to 1000 years
This commit is contained in:
Jose Diaz-Gonzalez
2022-05-11 22:42:31 -04:00
committed by GitHub

View File

@@ -1,6 +1,6 @@
#!/bin/bash #!/bin/bash
pushd /var/lib/postgresql/data >/dev/null pushd /var/lib/postgresql/data >/dev/null
openssl req -new -newkey rsa:4096 -x509 -nodes -out server.crt -keyout server.key -batch openssl req -new -newkey rsa:4096 -x509 -days 365000 -nodes -out server.crt -keyout server.key -batch
chmod 600 server.key chmod 600 server.key
sed -i "s/^#ssl = off/ssl = on/" postgresql.conf sed -i "s/^#ssl = off/ssl = on/" postgresql.conf
sed -i "s/^#ssl_ciphers =.*/ssl_ciphers = 'AES256+EECDH:AES256+EDH'/" postgresql.conf sed -i "s/^#ssl_ciphers =.*/ssl_ciphers = 'AES256+EECDH:AES256+EDH'/" postgresql.conf