[FOLIO-2406] SSL/TLS, SCRAM-SHA-256, migration to PostgreSQL 10 (or higher) Created: 18/Dec/19 Updated: 15/Jun/20 Resolved: 20/Dec/19 |
|
| Status: | Closed |
| Project: | FOLIO |
| Components: | None |
| Affects versions: | None |
| Fix versions: | None |
| Type: | Task | Priority: | P2 |
| Reporter: | Johannes Drexl | Assignee: | Unassigned |
| Resolution: | Duplicate | Votes: | 0 |
| Labels: | postgres, privacy, security | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original estimate: | Not Specified | ||
| Issue links: |
|
||||||||||||||||||||||||||||||||||||
| Sprint: | |||||||||||||||||||||||||||||||||||||
| Description |
|
Okapi and probably all modules are using legacy (though still supported) postgres libraries, which have major drawbacks and sometimes seem to be not correctly implemented anyway.
Additional note: Enable SSL server certificate pinning when upgrading |
| Comments |
| Comment by Julian Ladisch [ 19/Dec/19 ] |
|
Thank you for your report. It seems that you've combined 4 issues into a single report: Can you create a separate Jira issue for each of them so that they can be handled independently? Can you check whether
Can you report 2. against OKAPI project? https://folio-org.atlassian.net/projects/OKAPI/issues When creating the issue for 4. can you be more specific in which part of FOLIO you noticed this problem (for example mod-inventory-storage, or in Okapi)? After creating the separate Jira issues please link
|
| Comment by Johannes Drexl [ 20/Dec/19 ] |
|
Split into multiple tickets: https://folio-org.atlassian.net/browse/FOLIO-2410 https://folio-org.atlassian.net/browse/OKAPI-787 -> https://folio-org.atlassian.net/browse/FOLIO-2412 https://folio-org.atlassian.net/browse/FOLIO-2411 Can't link and close issues, but if Hkaplanian would be so nice to do that for me 😉 As for
|
| Comment by Julian Ladisch [ 20/Dec/19 ] |
|
Thank you Johannes, I've linked them! |