Welcome! Log In Create A New Profile

Advanced

Upstream certificate validation - Servers in a server group

Nitsan Matsliah via nginx
March 01, 2022 04:32AM
Assuming I have 2 servers in an upstream server group:

1. Test1.server.local
2. Test2.server.local
Each one of these servers holds their own FQDN in their respective certificates.
Test1.server.local will have test1.server.local as its subject and subject alternative name in the certificate it serves.
Test2.server.local will have test2.server.local as its subject and subject alternative name in the certificate it serves.

Now, let’s assume that the name of the upstream group or proxy_ssl_name is Test.server.local, nginx will compare the subject name from each certificate (either test1.server.local or test2.server.local) to the upstream group name - test.server.local and would complain about a mismatch.
Unless test.server.local is added to each upstream server certificate this issue will persist.

Is there any way around this using maybe nginx plus or any other alternative?

Thanks
This e-mail and the information it contains may be privileged and/or confidential. It is intended solely for the use of the named recipient(s). If you are not the intended recipient you may not disclose, copy, distribute or retain any part of this message or attachments. If you have received this e-mail in error please notify the sender immediately [by clicking 'Reply'] and delete this e-mail.
_______________________________________________
nginx mailing list -- nginx@nginx.org
To unsubscribe send an email to nginx-leave@nginx.org
Subject Author Posted

Upstream certificate validation - Servers in a server group

Nitsan Matsliah via nginx March 01, 2022 04:32AM

Re: Upstream certificate validation - Servers in a server group

Maxim Dounin March 01, 2022 09:08AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 291
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready