Back to PostgreSQL
GSoC 2026

pgagroal: Advanced security

This project implements true end-to-end TLS pooling for pgagroal by decoupling the cryptographic state from the physical TCP socket. By implementing a clean-room TLSv1.2+ state machine using OpenSSL Memory BIOs, I will establish a Persistent Security Context that can be parked and resumed across pooled connections. Additional deliverables include a proxy-aware SCRAM-SHA-256-PLUS authentication pipeline, robust X.509 Client Certificate validation, and the decommissioning of legacy MD5 pathways to establish a modern, enterprise-grade security boundary.

Project details

Contributor

trxvor

Mentors

Not available

Technologies

Not listed in the archive