Welcome! Log In Create A New Profile

Advanced

Re: [PATCH 0 of 1] allow to use engine keyform for server private key

Maxim Dounin
March 25, 2014 01:12PM
Hello!

On Tue, Mar 25, 2014 at 04:45:46PM +0400, Tatiana Kondakova wrote:

> Hello.
> I'm a cryptography library developer (http://www.cryptopro.ru/).
> I want to make our server-side TLS worked with nginx, and we
> have engine for openssl, which successfully works with openssl
> utilities. But for security reasons we can not export the
> private key to a file, so our engine needs something like
> keyform ENGINE option.
> This option makes possible to use nginx with our library, with
> PKCS#11 tokens and with any other engine, which does not support
> private keys export.

While this functionality looks interesting, the patch certainly
needs more work before it will be possible to commit it. In
particular, the patch will break compilation with mail module, not
even talking about style issues.

I also can't say I like the way how it's expected to be
configured. There should be a better way to do this, probably
some parameter of the ssl_certificate_key directive ("format="? or
rather "engine="?) and/or some specific path prefix to load a key
from an engine.

--
Maxim Dounin
http://nginx.org/

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH 0 of 1] allow to use engine keyform for server private key

Tatiana Kondakova 794 March 25, 2014 08:42AM

[PATCH 1 of 1] add keyform option to SSL config to support loading private key from engine without exporting it to file

Tatiana Kondakova 322 March 25, 2014 08:42AM

Re: [PATCH 0 of 1] allow to use engine keyform for server private key

Maxim Dounin 316 March 25, 2014 01:12PM

Re: [PATCH 0 of 1] allow to use engine keyform for server private key

Piotr Sikora 258 March 25, 2014 02:26PM

Re: [PATCH 0 of 1] allow to use engine keyform for server private key

Maxim Dounin 286 March 25, 2014 02:44PM

Re: [PATCH 0 of 1] allow to use engine keyform for server private key

Piotr Sikora 368 March 25, 2014 04:12PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 213
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready