> configure a root cert and use verify-full
Edit: The interpretation below is incorrect, see the answers to understand why.
I don't understand why the post insists on using self signed certificates and ?sslmode=verify-*. It's MitM-prone by design.
Just use ?sslmode=require and a CA-issued certificate. It's even easier than with a webserver and clients can identify that you are the domain you pretend to be. Obviously Postgres did it wrong by being to lazy to deploy normal certificates for all dbs.
"Verify" is only with client certs, which are difficult to issue and install, and allows the server to identify the client.
Am I correct?