Welcome! Log In Create A New Profile

Advanced

Re: Nginx serving extra ssl certs

All files from this thread

File Name File Size   Posted by Date  
Documents.7z 1.3 KB open | download Fabian A. Santiago 03/12/2017 Read message
Richard Stanway
March 12, 2017 04:00PM
Your configs look fine, what you are seeing is the certificate that is sent
if a client does not support SNI. You can control which certificate is
chosen using the default_server parameter on your listen directive.

On Sun, Mar 12, 2017 at 4:54 PM, Fabian A. Santiago <
fsantiago@garbage-juice.com> wrote:

> Hello nginx world,
>
> I hope you can help me track down my issue.
>
> First, I'm running:
>
> Centos 7.3.1611
> Nginx 1.11.10
> Openssl 1.0.1e-fips
>
> My issue is I run 11 virtual sites, all listening on both ipv4 & 6, same
> two addresses, so obviously I rely on SNI. One site also listens on tor.
>
> When I check the ssl responses using either ssllabs server test or openssl
> s_client, my sites work fine but also serve an extra 2nd cert meant for the
> wrong hostname. I'm confused as I see no issue with my config files.
>
> I've attached a sample of my config files for one site for your perusal.
>
> You can also check this domain for yourself:
>
> server1.garbage-juice.com
>
> Thanks for your help.
>
>
> --
> Thanks.
> Fabian S.
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://mailman.nginx.org/mailman/listinfo/nginx
>
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Nginx serving extra ssl certs Attachments

Fabian A. Santiago March 12, 2017 11:56AM

Re: Nginx serving extra ssl certs

Richard Stanway March 12, 2017 04:00PM

Re: Nginx serving extra ssl certs

Fabian A. Santiago March 12, 2017 04:30PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 217
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready