Welcome! Log In Create A New Profile

Advanced

Re: Make ssl_certificate optional?

Julian Blake Kongslie
January 05, 2011 09:54AM
On Wed, Jan 05, 2011 at 10:48:33AM +0100, rainer@ultra-secure.de wrote:
> The question you should ask: is any client other than openssl actually
> capable of connecting successfully to such a server?
>
> IIRC, Firefox disabled all the "insecure" SSL-ciphers some time ago anyway...

Firefox gives an error on connection, but some other browsers connect
just fine; the nginx configuration with a useless certificate works just
fine in practice for my purposes, it's just not as easy to setup and
deploy. For what it's worth, the most common clients for these sites by
volume are all libcurl, which works just fine as long as you set the
don't-verify-peer bits.

We have some patches queued up to send to a few more mainstream
browsers that enable ADH and NULL ciphers such that the lock icons are
not displayed and the URL bar is not colored, leaving the user
experience exactly the same as if no SSL was involved at all, which
seems like a politically acceptable compromise for getting ADH support
back into Firefox et al.

Unfortunately, browsers are complicated and testing all the pathways
involved in treating a SSL connection as an insecure connection is not
trivial, so I'm tilting at your windmill first and will be fighting
those other battles another day.

> Rainer

Thanks,

--
-Julian Blake Kongslie <jblake@omgwallhack.org>
If this is a mailing list, please CC me on replies.

vim: set ft=text :
_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

Make ssl_certificate optional?

Julian Blake Kongslie January 05, 2011 01:46AM

Re: Make ssl_certificate optional?

Anonymous User January 05, 2011 04:52AM

Re: Make ssl_certificate optional?

Julian Blake Kongslie January 05, 2011 09:54AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 229
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready