Welcome! Log In Create A New Profile

Advanced

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin
April 18, 2014 12:54PM
Hello!

On Wed, Feb 12, 2014 at 08:29:08PM +0400, Maxim Dounin wrote:

> On Tue, Feb 11, 2014 at 01:16:41PM -0800, Piotr Sikora wrote:

[...]

> > > My original suggestion is as follows:
> > >
> > > proxy_ssl_name <value>
> > >
> > > default: $proxy_host
> > > complex value, controls a name used in SNI (if
> > > enabled)
> > >
> > > proxy_ssl_verify on|off
> > >
> > > default: off
> > > flag, controls if remote certificate verification is enabled
> > >
> > > proxy_ssl_verify_name on|off
> > >
> > > default: on
> > > flag, controls if remote certificate verification needs to
> > > check peer's name; must be explicitly switched off
> > > if certificate verification is switched on, but
> > > the name can't be checked due to too old OpenSSL
> >
> > Got it.
>
> Just a quick note:
>
> We've discussed this with Igor, and he thinks that peer's name
> should be always checked, without an ability to check switch the
> check off selectively. Mostly to simplify user experience. This
> implies that we either need our own peer's name check code, or
> verification won't work at all if OpenSSL is too old.

Another quick note:

I've committed backend SSL certificate verification code done
which mostly matches the above description:

http://hg.nginx.org/nginx/rev/7022564a9e0e
http://hg.nginx.org/nginx/rev/060c2e692b96

--
Maxim Dounin
http://nginx.org/

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 1148 February 04, 2014 09:32PM

[PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 419 February 05, 2014 01:56AM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin 399 February 06, 2014 11:12AM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 404 February 06, 2014 05:40PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin 371 February 06, 2014 07:04PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 403 February 06, 2014 09:42PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin 456 February 07, 2014 06:00AM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 455 February 11, 2014 04:18PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin 402 February 12, 2014 11:30AM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Valentin V. Bartenev 401 February 12, 2014 01:44PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Maxim Dounin 485 April 18, 2014 12:54PM

Re: [PATCH] SSL: add "{proxy, uwsgi}_ssl_verify" and supporting directives

Piotr Sikora 650 April 22, 2014 08:02AM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 133
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready