Welcome! Log In Create A New Profile

Advanced

Re: [PATCH] Mail: added support for SSL client certificate

April 14, 2014 03:34AM
Hello,

I forward Filipe's message, because it doesn't appear in forum's stack.
I'm ok with the proposal.

Kind Regards.
Franck Levionnois.


2014-04-07 10:35 GMT+02:00 Filipe Da Silva <fdasilvayy@gmail.com>:

> Hi,
>
> From the mail-auth-http module point of view, the Auth-Verify is a
> trivial information.
> Its value mostly depends of the current server configuration ( verify
> setting ).
> IMHO, it could be discard.
>
> About the various/duplicated headers related to the client
> certificate, a smart solution
> could be adding a 'auth_http_client_cert' setting.
>
> It could be either a kind of bit-field allowing to select the wanted
> headers one by one or a log level.
>
> Bit-field doesn't seems to be a part of nginx configuration usages.
> Instead, a short list of keywords could be defined, may be following
> the OpenSSL display one:
> http://www.openssl.org/docs/apps/x509.html#DISPLAY_OPTIONS
>
> Or, the auth_http_client_cert log levels could be :
> - none
> - basic -> just the Certificate Subject
> - detailed : Subject, Issuer
> - complete : Subject, Issuer, sha1 hash
> - full -> whole certificate
> IMHO, 'detailled' should be the default settings, if not configured.
>
> Regards,
> Filipe da Silva
>
> 2014-03-18 18:40 GMT+01:00 Franck Levionnois <flevionnois@gmail.com>:
> > Hello,
> >
> > It doesn't seem to exist a standard for this header name. Apache and F5
> let
> > the user choose it, but this make the configuration more complicated. I
> > don't think that the name is a problem, because it can be set on the
> > authorization server.
> >
> > If the certificate is transmited, all other informations are duplicated
> > (except Auth-Verify). Forwarding the certificate is the most usefull,
> > because it can be used to make controls on its properties.
> >
> > Kind regards,
> > Franck Levionnois.
> >
> >
> >
> > 2014-03-07 12:31 GMT+01:00 Maxim Dounin <mdounin@mdounin.ru>:
> >
> >> Hello!
> >>
> >> On Fri, Mar 07, 2014 at 09:40:11AM +0100, Franck Levionnois wrote:
> >>
> >> > Hello,
> >> > I haven't seen any comment on this patch. Is it ok for you ?
> >>
> >> Sorry, I haven't yet had a time to look into it in detail.
> >>
> >> Most problematic part is still auth_http protocol changes - in
> >> particular, headers send and names used for them. I tend to think
> >> there should be better names, and probably we can safely omit some
> >> information as duplicate/unneeded.
> >>
> >> --
> >> Maxim Dounin
> >> http://nginx.org/
> >>
> >> _______________________________________________
> >> nginx-devel mailing list
> >> nginx-devel@nginx.org
> >> http://mailman.nginx.org/mailman/listinfo/nginx-devel
> >
> >
>
_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] Mail: added support for SSL client certificate

Filipe da Silva 1327 January 25, 2014 03:48AM

Re: [PATCH] Mail: added support for SSL client certificate

Maxim Dounin 469 January 28, 2014 09:20AM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 580 January 28, 2014 12:42PM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 583 February 10, 2014 08:10AM

Re: [PATCH] Mail: added support for SSL client certificate

Maxim Dounin 513 February 11, 2014 07:42AM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 566 February 14, 2014 05:42AM

[PATCH] Mail: added support for SSL client certificate

Franck Levionnois 512 February 21, 2014 05:12AM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 492 February 21, 2014 06:48AM

[PATCH] Mail: added support for SSL client certificate

Franck Levionnois 644 February 21, 2014 06:50AM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 459 March 07, 2014 03:42AM

Re: [PATCH] Mail: added support for SSL client certificate

Maxim Dounin 460 March 07, 2014 06:32AM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 475 March 18, 2014 01:42PM

Re: [PATCH] Mail: added support for SSL client certificate

Franck Levionnois 475 April 14, 2014 03:34AM

Re: [PATCH] Mail: added support for SSL client certificate

Filipe Da Silva 478 June 16, 2014 04:24PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 131
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready