diff --git a/doc/src/sgml/libpq.sgml b/doc/src/sgml/libpq.sgml index e1a1d5a1c58..a9d0d98d04d 100644 --- a/doc/src/sgml/libpq.sgml +++ b/doc/src/sgml/libpq.sgml @@ -1,4 +1,4 @@ - + <application>libpq</application> - C Library @@ -283,6 +283,15 @@ only if the certificate also has just the IP address in the cn field. + + + If the cn attribute in the certificate sent by the + server starts with an asterisk (*), it will be treated + as a wildcard. This wildcard can only be present at the start of + the value, and will match all characters except a + dot (.). This means the certificate will not match + subdomains. +