Welcome! Log In Create A New Profile

Advanced

Re: Provide site-specific SSL cert on behalf of clients

May 25, 2011 06:36AM
On Wed, May 25, 2011 at 06:27:15AM -0400, urschrei wrote:
> Igor,
> just to make sure I'm not misunderstanding you:
>
> Usually, what happens is this:
>
> I install an SSL cert (let's call it certA) in a client browser, so I
> can access https site A, which requires it.
>
> But if I have a lot of clients, I'd ideally like to have nginx proxy
> this cert, on behalf of my clients, so I don't have to install it for
> each of them. Are you saying that in order for nginx to proxy the cert,
> I'll first have to generate a CA cert on the server, and then sign the
> client cert (certA) with it? Won't this result in a self-signed
> certificate warning every time a client tries to access site A?

nginx as a client does not currently support a client certificate
when it proxies a request to HTTPS backend (B). However, I do not see
any security advantage when many clients look like one for backend B.


--
Igor Sysoev

_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

Provide site-specific SSL cert on behalf of clients

urschrei May 24, 2011 05:04PM

Re: Provide site-specific SSL cert on behalf of clients

Igor Sysoev May 25, 2011 02:14AM

Re: Provide site-specific SSL cert on behalf of clients

urschrei May 25, 2011 05:15AM

Re: Provide site-specific SSL cert on behalf of clients

Igor Sysoev May 25, 2011 05:20AM

Re: Provide site-specific SSL cert on behalf of clients

urschrei May 25, 2011 06:27AM

Re: Provide site-specific SSL cert on behalf of clients

Igor Sysoev May 25, 2011 06:36AM

Re: Provide site-specific SSL cert on behalf of clients

urschrei May 25, 2011 06:46AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 318
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready