Welcome! Log In Create A New Profile

Advanced

Re: this may be a dumb ssl question, but here goes...

October 10, 2012 05:18PM
I think I might have found my answer to this.

I can generate my own (or use any different) CA and add that in
ssl_client_certificate <path>;
And then set ssl_verify_client on;

This appears to work in initial testing. So my follow-up is:
1) Does this sound like the way to make my original question work?
2) Can I revoke certificates, and will nginx check a revocation list of
some kind?

Thanks again,
AJ


On 10/10/2012 2:14 PM, AJ Weber wrote:
> Can I install and configure nginx to use a "public"/global CA's SSL
> Certificate like Verisign, AND force (require) the use of client SSL
> certificates, AND allow those client/browser-certificates to be from a
> different CA/root? For example, openca or some self-signed setup that
> I use to just distribute client certificates to my registered users?
>
> Let me know if I am not asking the question correctly.
>
> Thanks,
> AJ
>

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

this may be a dumb ssl question, but here goes...

aweber October 10, 2012 02:16PM

Re: this may be a dumb ssl question, but here goes...

aweber October 10, 2012 05:18PM

Re: this may be a dumb ssl question, but here goes...

Maxim Dounin October 10, 2012 06:52PM

Re: this may be a dumb ssl question, but here goes...

aweber October 10, 2012 07:18PM

Re: this may be a dumb ssl question, but here goes...

aweber October 11, 2012 11:38AM

Re: this may be a dumb ssl question, but here goes...

Maxim Dounin October 11, 2012 05:54PM

Re: this may be a dumb ssl question, but here goes...

aweber October 11, 2012 06:08PM

Re: this may be a dumb ssl question, but here goes...

Maxim Dounin October 11, 2012 06:22PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 143
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready