Jonathan Matthews
November 26, 2013 06:02PM
On 26 November 2013 22:48, Radha Venkatesh (radvenka)
<radvenka@cisco.com> wrote:
> Jonathan,
>
> The requirement is that we match an existing hostname entry in /etc/hosts with the Client certificate CN (CN has to be the hostname of the client).

That's not really saying anything /new/, is it? ;-)

Here are some examples of different things that your requirement could mean:

1) Do you want to ensure that the CN that is presented merely *exists*
in /etc/hosts?
2) Do you want to ensure that the connection came from an IP that the
CN's entry in /etc/hosts matches?
3) Both of #1 and #2 combined?

Please give some representative examples of CNs being presented,
/etc/hosts contents, and the allow/deny behaviour you want to see
based on those combinations. Your requirement, whilst obvious and
clear to yourself, is not clear to some people (well, me at least!) as
they don't have their head deep inside your project.

Regards,
Jonathan

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Need to compare client certificate CN with an entry in /etc/hosts

Radha Venkatesh (radvenka) November 26, 2013 02:22PM

Re: Need to compare client certificate CN with an entry in /etc/hosts

Jonathan Matthews November 26, 2013 02:56PM

RE: Need to compare client certificate CN with an entry in /etc/hosts

Radha Venkatesh (radvenka) November 26, 2013 05:50PM

RE: Need to compare client certificate CN with an entry in /etc/hosts

GreenGecko November 26, 2013 05:56PM

Re: Need to compare client certificate CN with an entry in /etc/hosts

Jonathan Matthews November 26, 2013 06:02PM

Re: Need to compare client certificate CN with an entry in /etc/hosts

Francis Daly November 26, 2013 06:16PM

RE: Need to compare client certificate CN with an entry in /etc/hosts

Radha Venkatesh (radvenka) November 26, 2013 07:02PM

Re: Need to compare client certificate CN with an entry in /etc/hosts

Francis Daly November 27, 2013 06:08PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 208
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready