Welcome! Log In Create A New Profile

Advanced

[PATCH] Add ssl_client_not_before and ssl_client_not_after request

Andrey Kulikov
September 07, 2015 01:20PM
Hello,

Nginx SSL module allow to use some variables:
http://nginx.org/en/docs/http/ngx_http_ssl_module.html#variables
But sometimes tey are not enough.

Please find attached patch, adding two more:
$ssl_client_not_before - Validity date from client certificate 'Not Before'
$ssl_client_not_after - Validity date from client certificate 'Not After'

After applying changes you may use them in configuration along with other
variables:

location /test_headers/ {
proxy_set_header X-ClientCert-SubjectSerial $ssl_client_serial;
proxy_set_header X-ClientCert-NotBefore $ssl_client_not_before;
proxy_set_header X-ClientCert-NotAfter $ssl_client_not_after;
proxy_pass http://192.168.88.156/;
}

And it will appears in (in this case) in proxied content in the following
form:

X-ClientCert-SubjectSerial: 120005C82FBE782D06D89FF14800000005C82F
X-ClientCert-NotBefore: Jul 9 22:20:31 2015 GMT
X-ClientCert-NotAfter: Oct 9 22:30:31 2015 GMT


Tested on 1.8.0, tested that it can be cleanly applied to 1.9.4.

Feel free to ask any questions regarding this matter.

Best wishes,
Andrey
_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] Add ssl_client_not_before and ssl_client_not_after request

Andrey Kulikov 633 September 07, 2015 01:20PM

Re: [PATCH] Add ssl_client_not_before and ssl_client_not_after request

Kaj Niemi 251 September 07, 2015 01:44PM

Re: [PATCH] Add ssl_client_not_before and ssl_client_not_after request

Maxim Dounin 253 September 07, 2015 02:06PM

Re: [PATCH] Add ssl_client_not_before and ssl_client_not_after request

Andrey Kulikov 262 September 07, 2015 02:24PM

Re: [PATCH] Add ssl_client_not_before and ssl_client_not_after request

Maxim Dounin 286 September 10, 2015 11:38AM

Re: [PATCH] Add ssl_client_not_before and ssl_client_not_after request

Andrey Kulikov 321 September 10, 2015 12:30PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 136
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready