Mercurial > hg > nginx-site
annotate xml/ru/docs/stream/ngx_stream_ssl_module.xml @ 2334:dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
author | Yaroslav Zhuravlev <yar@nginx.com> |
---|---|
date | Tue, 26 Feb 2019 18:33:47 +0300 |
parents | e2e71f9477a8 |
children | 8e35f3af574b |
rev | line source |
---|---|
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
1 <?xml version="1.0"?> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
2 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
3 <!-- |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
4 Copyright (C) Nginx, Inc. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
5 --> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
6 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
7 <!DOCTYPE module SYSTEM "../../../../dtd/module.dtd"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
8 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
9 <module name="Модуль ngx_stream_ssl_module" |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
10 link="/ru/docs/stream/ngx_stream_ssl_module.html" |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
11 lang="ru" |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
12 rev="20"> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
13 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
14 <section id="summary"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
15 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
16 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
17 Модуль <literal>ngx_stream_ssl_module</literal> (1.9.0) |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
18 обеспечивает необходимую поддержку для работы |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
19 прокси-сервера по протоколу SSL/TLS. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
20 По умолчанию этот модуль не собирается, его сборку необходимо |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
21 разрешить с помощью конфигурационного параметра |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
22 <literal>--with-stream_ssl_module</literal>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
23 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
24 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
25 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
26 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
27 |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
28 <section id="example" name="Пример конфигурации"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
29 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
30 <para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
31 Для уменьшения загрузки процессора рекомендуется |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
32 <list type="bullet"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
33 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
34 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
35 установить число |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
36 <link doc="../ngx_core_module.xml" id="worker_processes">рабочих процессов</link> |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
37 равным числу процессоров, |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
38 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
39 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
40 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
41 включить <link id="ssl_session_cache_shared">разделяемый</link> кэш сессий, |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
42 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
43 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
44 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
45 выключить <link id="ssl_session_cache_builtin">встроенный</link> кэш сессий |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
46 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
47 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
48 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
49 и, возможно, увеличить <link id="ssl_session_timeout">время жизни</link> сессии |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
50 (по умолчанию 5 минут): |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
51 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
52 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
53 </list> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
54 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
55 <example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
56 <emphasis>worker_processes auto;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
57 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
58 stream { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
59 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
60 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
61 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
62 server { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
63 listen 12345 ssl; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
64 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
65 ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
66 ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
67 ssl_certificate /usr/local/nginx/conf/cert.pem; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
68 ssl_certificate_key /usr/local/nginx/conf/cert.key; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
69 <emphasis>ssl_session_cache shared:SSL:10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
70 <emphasis>ssl_session_timeout 10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
71 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
72 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
73 } |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
74 </example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
75 </para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
76 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
77 </section> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
78 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
79 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
80 <section id="directives" name="Директивы"> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
81 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
82 <directive name="ssl_certificate"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
83 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
84 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
85 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
86 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
87 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
88 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
89 Указывает <value>файл</value> с сертификатом в формате PEM |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
90 для данного сервера. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
91 Если вместе с основным сертификатом нужно указать промежуточные, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
92 то они должны находиться в этом же файле в следующем порядке — сначала |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
93 основной сертификат, а затем промежуточные. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
94 В этом же файле может находиться секретный ключ в формате PEM. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
95 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
96 |
1726
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
97 <para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
98 Начиная с версии 1.11.0 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
99 эта директива может быть указана несколько раз |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
100 для загрузки сертификатов разных типов, например RSA и ECDSA: |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
101 <example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
102 server { |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
103 listen 12345 ssl; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
104 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
105 ssl_certificate example.com.rsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
106 ssl_certificate_key example.com.rsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
107 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
108 ssl_certificate example.com.ecdsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
109 ssl_certificate_key example.com.ecdsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
110 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
111 ... |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
112 } |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
113 </example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
114 <note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
115 Возможность задавать отдельные цепочки сертификатов для разных сертификатов |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
116 есть только в OpenSSL 1.0.2 и выше. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
117 Для более старых версий следует указывать только одну цепочку сертификатов. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
118 </note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
119 </para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
120 |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
121 <para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
122 Начиная с версии 1.15.9 в имени файла можно использовать переменные |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
123 при использовании OpenSSL 1.0.2 и выше: |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
124 <example> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
125 ssl_certificate $ssl_server_name.crt; |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
126 ssl_certificate_key $ssl_server_name.key; |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
127 </example> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
128 Однако нужно учитывать, что при использовании переменных |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
129 сертификат загружается при каждой операции SSL handshake, |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
130 что может отрицательно влиять на производительность. |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
131 </para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
132 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
133 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
134 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
135 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
136 <directive name="ssl_certificate_key"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
137 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
138 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
139 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
140 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
141 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
142 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
143 Указывает <value>файл</value> с секретным ключом в формате PEM |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
144 для данного сервера. |
1456
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
145 </para> |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
146 |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
147 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
148 Вместо <value>файла</value> можно указать значение |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
149 <literal>engine</literal>:<value>имя</value>:<value>id</value>, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
150 которое загружает ключ с указанным <value>id</value> |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
151 из OpenSSL engine с заданным <value>именем</value>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
152 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
153 |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
154 <para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
155 Начиная с версии 1.15.9 в имени файла можно использовать переменные |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
156 при использовании OpenSSL 1.0.2 и выше. |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
157 </para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
158 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
159 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
160 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
161 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
162 <directive name="ssl_ciphers"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
163 <syntax><value>шифры</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
164 <default>HIGH:!aNULL:!MD5</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
165 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
166 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
167 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
168 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
169 Описывает разрешённые шифры. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
170 Шифры задаются в формате, поддерживаемом библиотекой |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
171 OpenSSL, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
172 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
173 ssl_ciphers ALL:!aNULL:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
174 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
175 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
176 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
177 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
178 Полный список можно посмотреть с помощью команды |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
179 “<command>openssl ciphers</command>”. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
180 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
181 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
182 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
183 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
184 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
185 <directive name="ssl_client_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
186 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
187 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
188 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
189 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
190 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
191 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
192 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
193 Указывает <value>файл</value> с доверенными сертификатами CA в формате |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
194 PEM, которые используются для |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
195 <link id="ssl_verify_client">проверки</link> клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
196 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
197 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
198 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
199 Список сертификатов будет отправляться клиентам. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
200 Если это нежелательно, можно воспользоваться директивой |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
201 <link id="ssl_trusted_certificate"/>. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
202 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
203 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
204 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
205 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
206 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
207 <directive name="ssl_crl"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
208 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
209 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
210 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
211 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
212 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
213 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
214 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
215 Указывает <value>файл</value> с отозванными сертификатами (CRL) |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
216 в формате PEM, используемыми для |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
217 <link id="ssl_verify_client">проверки</link> клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
218 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
219 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
220 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
221 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
222 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
223 <directive name="ssl_dhparam"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
224 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
225 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
226 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
227 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
228 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
229 <para> |
1706
6f5497797cde
Changed "EDH ciphers" to "DHE ciphers".
Maxim Dounin <mdounin@mdounin.ru>
parents:
1521
diff
changeset
|
230 Указывает <value>файл</value> с параметрами для DHE-шифров. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
231 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
232 |
2296
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
233 <para> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
234 По умолчанию параметры не заданы, |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
235 и соответственно DHE-шифры не будут использоваться. |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
236 <note> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
237 До версии 1.11.0 по умолчанию использовались встроенные параметры. |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
238 </note> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
239 </para> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
240 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
241 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
242 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
243 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
244 <directive name="ssl_ecdh_curve"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
245 <syntax><value>кривая</value></syntax> |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
246 <default>auto</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
247 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
248 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
249 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
250 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
251 Задаёт <value>кривую</value> для ECDHE-шифров. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
252 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
253 |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
254 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
255 При использовании OpenSSL 1.0.2 и выше |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
256 можно указывать несколько кривых (1.11.0), например: |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
257 <example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
258 ssl_ecdh_curve prime256v1:secp384r1; |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
259 </example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
260 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
261 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
262 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
263 Специальное значение <literal>auto</literal> (1.11.0) соответствует |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
264 встроенному в библиотеку OpenSSL списку кривых для OpenSSL 1.0.2 и выше, |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
265 или <literal>prime256v1</literal> для более старых версий. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
266 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
267 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
268 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
269 <note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
270 До версии 1.11.0 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
271 по умолчанию использовалась кривая <literal>prime256v1</literal>. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
272 </note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
273 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
274 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
275 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
276 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
277 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
278 <directive name="ssl_handshake_timeout"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
279 <syntax><value>время</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
280 <default>60s</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
281 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
282 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
283 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
284 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
285 Задаёт таймаут для завершения операции SSL handshake. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
286 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
287 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
288 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
289 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
290 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
291 <directive name="ssl_password_file"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
292 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
293 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
294 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
295 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
296 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
297 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
298 Задаёт <value>файл</value> с паролями от |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
299 <link id="ssl_certificate_key">секретных ключей</link>, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
300 где каждый пароль указан на отдельной строке. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
301 Пароли применяются по очереди в момент загрузки ключа. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
302 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
303 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
304 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
305 Пример: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
306 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
307 stream { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
308 ssl_password_file /etc/keys/global.pass; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
309 ... |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
310 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
311 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
312 listen 127.0.0.1:12345; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
313 ssl_certificate_key /etc/keys/first.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
314 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
315 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
316 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
317 listen 127.0.0.1:12346; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
318 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
319 # вместо файла можно указать именованный канал |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
320 ssl_password_file /etc/keys/fifo; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
321 ssl_certificate_key /etc/keys/second.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
322 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
323 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
324 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
325 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
326 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
327 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
328 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
329 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
330 <directive name="ssl_prefer_server_ciphers"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
331 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
332 <default>off</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
333 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
334 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
335 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
336 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
337 Указывает, чтобы при использовании протоколов SSLv3 и TLS |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
338 серверные шифры были более приоритетны, чем клиентские. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
339 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
340 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
341 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
342 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
343 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
344 <directive name="ssl_protocols"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
345 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
346 [<literal>SSLv2</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
347 [<literal>SSLv3</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
348 [<literal>TLSv1</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
349 [<literal>TLSv1.1</literal>] |
1978
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
350 [<literal>TLSv1.2</literal>] |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
351 [<literal>TLSv1.3</literal>]</syntax> |
1499
3687cc9a3592
Removed SSLv3 from the default value of ssl_protocols and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1462
diff
changeset
|
352 <default>TLSv1 TLSv1.1 TLSv1.2</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
353 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
354 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
355 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
356 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
357 Разрешает указанные протоколы. |
1978
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
358 <note> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
359 Параметры <literal>TLSv1.1</literal> и <literal>TLSv1.2</literal> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
360 работают только при использовании OpenSSL 1.0.1 и выше. |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
361 </note> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
362 <note> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
363 Параметр <literal>TLSv1.3</literal> (1.13.0) работает только |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
364 при использовании OpenSSL 1.1.1, собранной с поддержкой TLSv1.3. |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
365 </note> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
366 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
367 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
368 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
369 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
370 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
371 <directive name="ssl_session_cache"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
372 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
373 <literal>off</literal> | |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
374 <literal>none</literal> | |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
375 [<literal>builtin</literal>[:<value>размер</value>]] |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
376 [<literal>shared</literal>:<value>название</value>:<value>размер</value>]</syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
377 <default>none</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
378 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
379 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
380 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
381 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
382 Задаёт тип и размеры кэшей для хранения параметров сессий. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
383 Тип кэша может быть следующим: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
384 <list type="tag"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
385 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
386 <tag-name><literal>off</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
387 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
388 жёсткое запрещение использования кэша сессий: |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
389 nginx явно сообщает клиенту, что сессии не могут использоваться повторно. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
390 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
391 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
392 <tag-name><literal>none</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
393 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
394 мягкое запрещение использования кэша сессий: |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
395 nginx сообщает клиенту, что сессии могут использоваться повторно, но |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
396 на самом деле не хранит параметры сессии в кэше. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
397 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
398 |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
399 <tag-name id="ssl_session_cache_builtin"><literal>builtin</literal></tag-name> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
400 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
401 встроенный в OpenSSL кэш, используется в рамках только одного рабочего процесса. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
402 Размер кэша задаётся в сессиях. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
403 Если размер не задан, то он равен 20480 сессиям. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
404 Использование встроенного кэша может вести к фрагментации памяти. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
405 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
406 |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
407 <tag-name id="ssl_session_cache_shared"><literal>shared</literal></tag-name> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
408 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
409 кэш, разделяемый между всеми рабочими процессами. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
410 Размер кэша задаётся в байтах, в 1 мегабайт может поместиться |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
411 около 4000 сессий. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
412 У каждого разделяемого кэша должно быть произвольное название. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
413 Кэш с одинаковым названием может использоваться в нескольких |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
414 серверах. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
415 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
416 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
417 </list> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
418 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
419 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
420 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
421 Можно использовать одновременно оба типа кэша, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
422 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
423 ssl_session_cache builtin:1000 shared:SSL:10m; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
424 </example> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
425 однако использование только разделяемого кэша без встроенного должно |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
426 быть более эффективным. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
427 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
428 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
429 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
430 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
431 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
432 <directive name="ssl_session_ticket_key"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
433 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
434 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
435 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
436 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
437 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
438 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
439 Задаёт <value>файл</value> с секретным ключом, применяемым при шифровании и |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
440 расшифровании TLS session tickets. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
441 Директива необходима, если один и тот же ключ нужно использовать |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
442 на нескольких серверах. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
443 По умолчанию используется случайно сгенерированный ключ. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
444 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
445 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
446 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
447 Если указано несколько ключей, то только первый ключ |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
448 используется для шифрования TLS session tickets. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
449 Это позволяет настроить ротацию ключей, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
450 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
451 ssl_session_ticket_key current.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
452 ssl_session_ticket_key previous.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
453 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
454 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
455 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
456 <para> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
457 <value>Файл</value> должен содержать 80 или 48 байт случайных данных |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
458 и может быть создан следующей командой: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
459 <example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
460 openssl rand 80 > ticket.key |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
461 </example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
462 В зависимости от размера файла для шифрования будет использоваться либо |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
463 AES256 (для 80-байтных ключей, 1.11.8), либо AES128 (для 48-байтных ключей). |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
464 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
465 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
466 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
467 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
468 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
469 <directive name="ssl_session_tickets"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
470 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
471 <default>on</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
472 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
473 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
474 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
475 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
476 Разрешает или запрещает возобновление сессий при помощи |
1923
66a30a380fba
Fixed links to tools.ietf.org.
Ruslan Ermilov <ru@nginx.com>
parents:
1877
diff
changeset
|
477 <link url="https://tools.ietf.org/html/rfc5077">TLS session tickets</link>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
478 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
479 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
480 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
481 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
482 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
483 <directive name="ssl_session_timeout"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
484 <syntax><value>время</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
485 <default>5m</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
486 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
487 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
488 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
489 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
490 Задаёт время, в течение которого клиент может повторно |
1785
3fa0944ddc6a
Removed info about session cache from ssl_session_timeout.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1745
diff
changeset
|
491 использовать параметры сессии. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
492 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
493 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
494 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
495 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
496 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
497 <directive name="ssl_trusted_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
498 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
499 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
500 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
501 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
502 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
503 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
504 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
505 Задаёт <value>файл</value> с доверенными сертификатами CA в формате PEM, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
506 которые используются для <link id="ssl_verify_client">проверки</link> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
507 клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
508 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
509 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
510 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
511 В отличие от <link id="ssl_client_certificate"/>, список этих сертификатов |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
512 не будет отправляться клиентам. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
513 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
514 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
515 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
516 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
517 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
518 <directive name="ssl_verify_client"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
519 <syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
520 <literal>on</literal> | <literal>off</literal> | |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
521 <literal>optional</literal> | <literal>optional_no_ca</literal></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
522 <default>off</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
523 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
524 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
525 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
526 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
527 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
528 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
529 Разрешает проверку клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
530 Результат проверки доступен через переменную |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
531 <link id="var_ssl_client_verify">$ssl_client_verify</link>. |
1876
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
532 Если при проверке клиентского сертификата произошла ошибка |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
533 или клиент не предоставил требуемый сертификат, |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
534 соединение закрывается. |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
535 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
536 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
537 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
538 Параметр <literal>optional</literal> запрашивает клиентский |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
539 сертификат, и если сертификат был предоставлен, проверяет его. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
540 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
541 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
542 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
543 Параметр <literal>optional_no_ca</literal> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
544 запрашивает сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
545 клиента, но не требует, чтобы он был подписан доверенным сертификатом CA. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
546 Это предназначено для случаев, когда фактическая проверка сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
547 осуществляется внешним по отношению к nginx’у сервисом. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
548 Содержимое сертификата доступно через переменную |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
549 <link id="var_ssl_client_cert">$ssl_client_cert</link>. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
550 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
551 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
552 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
553 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
554 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
555 <directive name="ssl_verify_depth"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
556 <syntax><value>число</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
557 <default>1</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
558 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
559 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
560 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
561 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
562 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
563 Устанавливает глубину проверки в цепочке клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
564 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
565 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
566 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
567 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
568 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
569 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
570 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
571 <section id="variables" name="Встроенные переменные"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
572 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
573 <para> |
1790
6da8d19f89c0
Corrected module name in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1785
diff
changeset
|
574 Модуль <literal>ngx_stream_ssl_module</literal> поддерживает переменные |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
575 начиная с версии 1.11.2. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
576 <list type="tag"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
577 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
578 <tag-name id="var_ssl_cipher"><var>$ssl_cipher</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
579 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
580 возвращает строку используемых шифров для установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
581 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
582 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
583 <tag-name id="var_ssl_ciphers"><var>$ssl_ciphers</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
584 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
585 возвращает список шифров, поддерживаемых клиентом (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
586 Известные шифры указаны по имени, неизвестные указаны в шестнадцатеричном виде, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
587 например: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
588 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
589 AES128-SHA:AES256-SHA:0x00ff |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
590 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
591 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
592 Переменная полностью поддерживается при использовании OpenSSL версии 1.0.2 |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
593 и выше. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
594 При использовании более старых версий переменная доступна |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
595 только для новых сессий и может содержать только известные шифры. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
596 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
597 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
598 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
599 <tag-name id="var_ssl_client_cert"><var>$ssl_client_cert</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
600 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
601 возвращает клиентский сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
602 для установленного SSL-соединения в формате PEM |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
603 перед каждой строкой которого, кроме первой, вставляется символ табуляции(1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
604 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
605 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
606 <tag-name id="var_ssl_client_fingerprint"><var>$ssl_client_fingerprint</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
607 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
608 возвращает SHA1-отпечаток клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
609 для установленного SSL-соединения (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
610 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
611 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
612 <tag-name id="var_ssl_client_i_dn"><var>$ssl_client_i_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
613 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
614 возвращает строку “issuer DN” клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
615 для установленного SSL-соединения согласно |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
616 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
617 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
618 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
619 <tag-name id="var_ssl_client_raw_cert"><var>$ssl_client_raw_cert</var> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
620 </tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
621 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
622 возвращает клиентский сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
623 для установленного SSL-соединения в формате PEM (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
624 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
625 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
626 <tag-name id="var_ssl_client_s_dn"><var>$ssl_client_s_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
627 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
628 возвращает строку “subject DN” клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
629 для установленного SSL-соединения согласно |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
630 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
631 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
632 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
633 <tag-name id="var_ssl_client_serial"><var>$ssl_client_serial</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
634 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
635 возвращает серийный номер клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
636 для установленного SSL-соединения (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
637 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
638 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
639 <tag-name id="var_ssl_client_v_end"><var>$ssl_client_v_end</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
640 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
641 возвращает дату окончания срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
642 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
643 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
644 <tag-name id="var_ssl_client_v_remain"><var>$ssl_client_v_remain</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
645 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
646 возвращает число дней, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
647 оставшихся до истечения срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
648 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
649 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
650 <tag-name id="var_ssl_client_v_start"><var>$ssl_client_v_start</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
651 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
652 возвращает дату начала срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
653 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
654 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
655 <tag-name id="var_ssl_client_verify"><var>$ssl_client_verify</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
656 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
657 возвращает результат проверки клиентского сертификата (1.11.8): |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
658 “<literal>SUCCESS</literal>”, “<literal>FAILED:</literal><value>reason</value>” |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
659 и, если сертификат не был предоставлен, “<literal>NONE</literal>”; |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
660 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
661 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
662 <tag-name id="var_ssl_curves"><var>$ssl_curves</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
663 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
664 возвращает список кривых, поддерживаемых клиентом (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
665 Известные кривые указаны по имени, неизвестные указаны в шестнадцатеричном виде, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
666 например: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
667 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
668 0x001d:prime256v1:secp521r1:secp384r1 |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
669 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
670 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
671 Переменная поддерживается при использовании OpenSSL версии 1.0.2 и выше. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
672 При использовании более старых версий значением переменной будет пустая строка. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
673 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
674 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
675 Переменная доступна только для новых сессий. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
676 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
677 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
678 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
679 <tag-name id="var_ssl_protocol"><var>$ssl_protocol</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
680 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
681 возвращает протокол установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
682 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
683 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
684 <tag-name id="var_ssl_server_name"><var>$ssl_server_name</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
685 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
686 возвращает имя сервера, запрошенное через |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
687 <link url="http://en.wikipedia.org/wiki/Server_Name_Indication">SNI</link>; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
688 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
689 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
690 <tag-name id="var_ssl_session_id"><var>$ssl_session_id</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
691 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
692 возвращает идентификатор сессии установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
693 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
694 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
695 <tag-name id="var_ssl_session_reused"><var>$ssl_session_reused</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
696 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
697 возвращает “<literal>r</literal>”, если сессия была использована повторно, |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
698 иначе “<literal>.</literal>”. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
699 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
700 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
701 </list> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
702 </para> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
703 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
704 </section> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
705 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
706 </module> |