Welcome! Log In Create A New Profile

Advanced

Accepting Multiple TLS Client Certificates

Johannes Gehrs
June 24, 2019 11:00AM
Hi,

as per our understanding one can provide a file with multiple certificates
as "ssl_client_certificate". Nginx would then accept any one of the
certificates. However, when we actually provided multiple certificates we
found that only the first one in the list was accepted.

In our test case we provided a chain of two certificates, a root cert and
the client certs signed by this CA. We tried both, concatenating the files
like this: "user1 user2 ca" and like this "user1 ca user2 ca". In all cases
just the first certificate was accepted.

Are we misunderstanding the expected behaviour of nginx, or is this a bug,
or are we maybe doing something wrong?

I will mention that we are using nginx in the nginx-ingress Kubernetes
package. We have tested with a version which uses nginx 1.15.10.

Thank you!
Johannes Gehrs
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Accepting Multiple TLS Client Certificates

Johannes Gehrs June 24, 2019 11:00AM

Re: Accepting Multiple TLS Client Certificates

Francis Daly June 25, 2019 06:28PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 233
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready