Fl4m3Ph03n1x

Fl4m3Ph03n1x

Background

We are making a proof of concept to use a postgres DB with Elixir. To achieve this we are using Postgrex.

Issue

The problem here is we need to connect to the DB using a certificate instead of a username and password. Unfortunately the documentation only has 1 example where one connects via username and password.

{:ok, pid} = Postgrex.start_link(hostname: "localhost", username: "postgres", password: "postgres", database: "postgres")

Research

I have read the documentation and I found that I can use the ssl and ssl_opts parameters when connecting to the DB: Postgrex — Postgrex v0.22.2

However, the documentation tells me to loo for the ssl docs, but no link is given.

It is the first time I am dealing with this kind of information in Elixir, I have no idea on how to proceed from here on.

Questions

  1. How do I connect to my postgres DB using a certificate and Postgrex?
  2. What are these ssl_opts documents the documentation refers to? How do they translate to Elixir code?

Showing Posts 1 to 5

hauleth

hauleth

It tells you to look into ssl module of Erlang standard library. To be exact you should look at tls_option/0. In the end it is keyword list with values specified in these type specs.

Fl4m3Ph03n1x

Fl4m3Ph03n1x OP

Would it be something like this?

{:ok, pid} = Postgrex.start_link(
  hostname: "localhost", 
  database: "postgres",
  ssl: true, 
  ssl_opts: [certfile: "/home/certs/my_cert.pem"], 
)
hauleth

hauleth

As documentation states that :certfile need to be string() which is Erlang’s string, in Elixir known as charlist you need to do this like that:

{:ok, pid} = Postgrex.start_link(
  hostname: "localhost", 
  database: "postgres",
  ssl: true, 
  ssl_opts: [certfile: '/home/certs/my_cert.pem'] 
)
voltone

voltone

It depends what you’re trying to achieve by using TLS. If you just want to authenticate with a client certificate while obscuring data from passive observers, then just a :certfile option may work, assuming this one file contains the client certificate, any intermediate certificates needed, and the private key. If the private key is stored in a separate file you’d have to pass a :keyfile option as well.

If you want to strongly authenticate the server, to prevent active (MitM) attacks, you’re going to have to pass in a few more options, starting with verify: :verify_peer, the server’s hostname (using the :server_name_indication option is easiest) and the trusted CA certificates (using the :cacertfile option, which may interfere with selection of the client certificate’s intermediate CA certs).

Fl4m3Ph03n1x

Fl4m3Ph03n1x OP

This is really valuable information. I felt quite lost reading through all of those examples, it’s always good to have some extra directions.

We’re not completely sure of our implementation, but if we have additional questions we’ll be sure to post them in the forum.

As a followup from this discussion I made a PR to improve the docs:

https://github.com/elixir-ecto/postgrex/pull/486

As a newcomer, I truly believe I needed more directions and the docs were at fault. This is my approach to improving them (the simplest approach I could think of, though I am still not convinced it’s enough).

Feel free to drop in with any suggestions on how to improve.

— All posts loaded —

Where Next? Top

Trending in Questions Top

stjefim
Hello! Suppose you are building workflow (order / task / payment) processing system with the following requirements: Each workflow con...
New
jonnycharles
I’m in search of an Elixir library that offers PDF generation capabilities similar to Ruby’s Prawn. While there have been discussions abo...
New
spammy
I’m looking to build a personal workflow to quickly deploy web applications written in elixir/phoenix, for local consumption (ie not on t...
New
dli
Before I dive in myself, did anyone successfully sprinkle Hologram into their existing LiveView app? Looking for hints regarding: Addi...
New
roeland
Kia ora, We have been using elixir-google-api to connect to Google Drive. However, with the updates to Tesla due to CVEs this is now bro...
New
bottlenecked
Hi all, I wanted to ask how the community is dealing with post-release steps. Today we have Ecto migrations, which make sure that the db...
New
rahultumpala
Hello, I have an Elixir backend that implements a custom protocol over TCP. I want to load test the backend and assess the performance o...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews