dbcli / dbcli/pgcli

Unable to use `pgcli service={service}`

Đang mở
#1,474 3 bình luận 2 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
13.4k
Fork
612
Merge trung bình
6 ngày 14 giờ
Pull request đã merge (30 ngày)
10

Mô tả

## Description

I am running a PostgreSQL server in a Docker container and using Secure TCP/IP Connections with SSL.

In my `postgresql.conf` file, I include the following lines:

```
ssl = on
ssl_ca_file = '/run/secrets/ca.crt'
ssl_cert_file = '/run/secrets/server.crt'
ssl_key_file = '/run/secrets/server.key'
# This setting is on by default but it’s always a good idea to
# be explicit when it comes to security.
ssl_prefer_server_ciphers = on
# TLS 1.3 will give the strongest security and is advised when
# controlling both server and clients.
ssl_min_protocol_version = 'TLSv1.3'
```

I have a `.pg_service.conf` file where I define a service named `{service}`:

```
[{service}]
host={host}
port={port}
user={user}
dbname={dbname}
sslmode=verify-full
sslrootcert=/path/to/ca.crt
sslcert=/path/to/user.crt
sslkey=/path/to/user.key
```

The command `psql service={service}` prompts for the password of the user included in the service definition and successfully connects to the specified database afterwards.

However, the command `pgcli service={service}` returns the following error message:

```
connection failed: FATAL: connection requires a valid client certificate
connection to server at "{host}", port {port} failed: FATAL: no pg_hba.conf entry for host "{host}", user "{user}", database "{dbname}", no encryption
```

In the PostgreSQL server logs I see the following entries:

```
postgres | 2024-08-06 10:50:35.387 GMT [117]: [1-1] user={user},db={dbname} FATAL: connection requires a valid client certificate
postgres | 2024-08-06 10:50:35.390 GMT [118]: [1-1] user={user},db={dbname} FATAL: no pg_hba.conf entry for host "{host}", user "{user}", database "{dbname}", no encryption
```

Note that the `pg_hba.conf` I am using contains the following line:

```
hostssl {dbname} {user} {host}/32 scram-sha-256 clientcert=verify-full
```

Surprisingly, the command `pgcli "postgresql://{user}@{host}/{dbname}?port={port}&sslmode=verify-full&sslkey=/path/to/user.key&sslcert=/path/to/user.crt&sslrootcert=/path/to/ca.crt"` successfully connects to the specified database after prompting for the user password. Same thing happens if I replace `pgcli` with `psql`.

Note that in the `.pg_service.conf` file I am using the very same paths to the `user.key`, `user.crt`, and `ca.crt` files.

## Your environment

- Debian 12 (bookworm)
- pgcli 4.1.0 - python 3.12.4 (installed with conda/mamba).
- Packages included in my conda/mamba env include, among other packages:
- ca-certificates 2024.7.4-hbcca054_0
- certifi 2024.7.4-pyhd8ed1ab_0
- openssl 3.3.1-h4bc722e_2
- postgresql 16.3-h8e811e2_0

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu bằng cách so sánh cách xử lý pgcli service={service} với lệnh URI PostgreSQL đang hoạt động, sử dụng các mục trong .pg_service.conf và các cài đặt kết nối PostgreSQL trong postgresql.conf và pg_hba.conf. Tái hiện lỗi bằng các lệnh được liệt kê và xác minh rằng các kết nối dựa trên service sử dụng cùng chứng chỉ máy khách, khóa, CA và các cài đặt SSL như dạng URI.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
postgresql, python
Lĩnh vực
cli, databases
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
52/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.