Skip to content

Allow disabling SNI on SSL Connections #5543

Description

@Evengard

When connecting through SSL, Npgsql sends along the SNI hostname, yet this is not always desired. The "conformant" libpq library doesn't seem to send SNI on SSL connections at all, and some server software (poolers, etc) are not playing well when there is an IP address sent in SNI (when you connect not to a hostname, but to an IP address).

It seems like there is no way to disable the SNI, as it seems to be just set from the ConnectionString Host parameter.

It would be appreciated, if there would be some way to disable the passing of SNI to the remote server.

Ref to this:

https://github.com/npgsql/npgsql/blob/eb050c0a0fd4b70f9d11c6d41027076e9e4e01c1/src/Npgsql/Internal/NpgsqlConnector.cs#L879C17-L883C1

Here not passing through Host to AuthenticateAsClient and instead passing an empty string will effectively disable SNI.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions