Mercurial > hg > nginx-quic
annotate conf/fastcgi_params @ 7367:bf1ac3dc1e68
SSL: fixed segfault on renegotiation (ticket #1646).
In e3ba4026c02d (1.15.4) nginx own renegotiation checks were disabled
if SSL_OP_NO_RENEGOTIATION is available. But since SSL_OP_NO_RENEGOTIATION
is only set on a connection, not in an SSL context, SSL_clear_option()
removed it as long as a matching virtual server was found. This resulted
in a segmentation fault similar to the one fixed in a6902a941279 (1.9.8),
affecting nginx built with OpenSSL 1.1.0h or higher.
To fix this, SSL_OP_NO_RENEGOTIATION is now explicitly set in
ngx_http_ssl_servername() after adjusting options. Additionally, instead
of c->ssl->renegotiation we now check c->ssl->handshaked, which seems
to be a more correct flag to test, and will prevent the segmentation fault
from happening even if SSL_OP_NO_RENEGOTIATION is not working.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Tue, 02 Oct 2018 17:46:18 +0300 |
parents | 62869a9b2e7d |
children |
rev | line source |
---|---|
537 | 1 |
2 fastcgi_param QUERY_STRING $query_string; | |
3 fastcgi_param REQUEST_METHOD $request_method; | |
4 fastcgi_param CONTENT_TYPE $content_type; | |
5 fastcgi_param CONTENT_LENGTH $content_length; | |
6 | |
7 fastcgi_param SCRIPT_NAME $fastcgi_script_name; | |
8 fastcgi_param REQUEST_URI $request_uri; | |
9 fastcgi_param DOCUMENT_URI $document_uri; | |
10 fastcgi_param DOCUMENT_ROOT $document_root; | |
11 fastcgi_param SERVER_PROTOCOL $server_protocol; | |
6168
62869a9b2e7d
Added the REQUEST_SCHEME parameter.
Maxim Dounin <mdounin@mdounin.ru>
parents:
4333
diff
changeset
|
12 fastcgi_param REQUEST_SCHEME $scheme; |
4333
352a7b025f2e
Added HTTPS param with Apache-like behaviour to fastcgi/scgi/uwsgi_params (fixes #38).
Valentin Bartenev <vbart@nginx.com>
parents:
1330
diff
changeset
|
13 fastcgi_param HTTPS $https if_not_empty; |
537 | 14 |
15 fastcgi_param GATEWAY_INTERFACE CGI/1.1; | |
1330 | 16 fastcgi_param SERVER_SOFTWARE nginx/$nginx_version; |
537 | 17 |
18 fastcgi_param REMOTE_ADDR $remote_addr; | |
19 fastcgi_param REMOTE_PORT $remote_port; | |
20 fastcgi_param SERVER_ADDR $server_addr; | |
21 fastcgi_param SERVER_PORT $server_port; | |
22 fastcgi_param SERVER_NAME $server_name; | |
23 | |
24 # PHP only, required if PHP was built with --enable-force-cgi-redirect | |
25 fastcgi_param REDIRECT_STATUS 200; |