Welcome! Log In Create A New Profile

Advanced

Re: question about client certs

Alex Samad
February 02, 2016 05:24PM
Yep I think thats what i was asking.

We have a home grown RP at work that does it and IIS used to do it,
apply cert requirements on part of the tree.



On 2 February 2016 at 20:56, Aleksandar Lazic <al-nginx@none.at> wrote:
> Dear Alex.
>
> Am 02-02-2016 04:32, schrieb Alex Samad:
>>
>> Hi
>>
>> Is it possible with nginx to do this
>>
>> https://www.abc.com
>> /
>> /noclientcert/
>> /clientcert/
>>
>>
>> so you can get to / with no client cert, but /clientcert/ you need a
>> cert, but for /noclientcert/ you don't need a cert.
>>
>> Looks like from the config doco you can only set it for the whole tree ...
>
>
> I would try to use this directives
>
> http://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_verify_client
> http://nginx.org/en/docs/http/ngx_http_map_module.html
>
> and in a map make something like this.
>
> map $ssl_client_cert $clientcert {
> default "";
> "~.*CLIENT_CERT_CHECK" clientcert;
> }
>
> and
>
> location $clientcert {
> }
>
> location no$clientcert {
> }
>
> is this possible ;-)?
>
> BR Aleks

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

question about client certs

Alex Samad February 01, 2016 10:34PM

Re: question about client certs

A. Schulze February 02, 2016 01:08AM

Re: question about client certs

B.R. February 02, 2016 02:54AM

Re: question about client certs

Aleksandar Lazic February 02, 2016 04:58AM

Re: question about client certs

Alex Samad February 02, 2016 05:24PM

Re: question about client certs

Aleksandar Lazic February 03, 2016 03:38AM

Re: question about client certs

Francis Daly February 03, 2016 04:24PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 139
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready