SSL connection for PostgreSQL communication
The SSL connection configuration is possible thanks to the support made by PostgreSQL. For reference: https://www.postgresql.org/docs/13/ssl-tcp.html
MetaDefender Core is tested against this mode on particular version 4.21.1
Generate SSL certificate for PostgreSQL server
Following instructions are for self-sign certificate. For production environment, making sure to use the certificate signed by your trusted CA.
Generate a private key
Sample output:
Type your desired password / pass phrase to encrypt the private key
Remove the pass phrase to automatically start up the PostgreSQL server
On Linux, make sure to set permission on the server.key file
Create a self-signed certificate
You will be prompted to enter detailed information which is incorporated into your self-signed certificate request.
For self-signed certificate, use the server ceriticate as the trusted root certificate:
Copy server.key, server.crt, root.crt to PostgreSQL data folder. For bundled local MetaDefender Core's PostgreSQL:
Windows: <Installation folder>\data\pg_data\
Linux: /var/lib/ometascan/pg_data/
Configure PostgreSQL server for SSL authentication connection
Create a custom config file (e.g. ssl.conf) for PostgreSQL. For bundled local MetaDefender Core's PostgreSQL:
Windows: <Installation folder>\postgres\ssl.conf
Linux: /var/lib/ometascan/postgres/ssl.conf
Content of ssl.conf:
Modify pg_hba.conf
For bundled local MetaDefender Core's PostgreSQL:
Windows: <Installation folder>\data\pg_data\pg_hba.conf
Linux:
/var/lib/ometascan/pg_data/pg_hba.conf
Add following (modify ::1/128 if needed to match with your environment requirement)
After the modify, the content of ssl.conf should be like this (example):
Commenting out all lines starting with "host" if you only want SSL connections to your PostgreSQL.
Reload the services
Standalone DB mode: Restart ometascan service (MetaDefender Core service)
Shared DB mode: Restart ometascan-pg
/ometascan-postgresql service (MetaDefender Core PostgreSQL service) and then ometascan service (MetaDefender Core service)
Test your SSL database connection:
This message indicate that you are now using SSL connection: