Welcome! Log In Create A New Profile

Advanced

Re: question about client certs

B.R.
February 02, 2016 02:54AM
Your question shows you need to understand how HTTP over TLS works.

TLS enciphers HTTP content, thus nothing is readable (either headers or
body).
How do you select the right certificate based on HTTP content? You can't.

Wait, Host-HTTP-Header-based certificate delivery exists, how is that
possible?
With TLS it is basically impossible, but it works though a TLS extension
called Server Name Indication (SNI). nginx docs talk about that:
http://nginx.org/en/docs/http/configuring_https_servers.html#name_based_https_servers

Now what you ask requires access to enciphered HTTP content.
Short answer: there is no way to do that, you will need to use different
servers, either using SNI (as Andreas suggested) or separate IP addresses.
---
*B. R.*

On Tue, Feb 2, 2016 at 7:05 AM, A. Schulze <sca@andreasschulze.de> wrote:

>
> Alex Samad:
>
> Is it possible with nginx to do this
>>
>> https://www.abc.com
>> /
>> /noclientcert/
>> /clientcert/
>>
>>
>> so you can get to / with no client cert, but /clientcert/ you need a
>> cert, but for /noclientcert/ you don't need a cert.
>>
>
> as far as I learned it's not possible and the usual answer
> to such feature requests is: "use different virtual hosts"
>
> Andreas
>
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://mailman.nginx.org/mailman/listinfo/nginx
>
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

question about client certs

Alex Samad February 01, 2016 10:34PM

Re: question about client certs

A. Schulze February 02, 2016 01:08AM

Re: question about client certs

B.R. February 02, 2016 02:54AM

Re: question about client certs

Aleksandar Lazic February 02, 2016 04:58AM

Re: question about client certs

Alex Samad February 02, 2016 05:24PM

Re: question about client certs

Aleksandar Lazic February 03, 2016 03:38AM

Re: question about client certs

Francis Daly February 03, 2016 04:24PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 197
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready