Mercurial > hg > nginx-site
annotate xml/en/docs/stream/ngx_stream_ssl_module.xml @ 2335:ff35d7b84a9b
Fixed date.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Tue, 26 Feb 2019 18:45:22 +0300 |
parents | dbe55598d3f6 |
children | 8e35f3af574b |
rev | line source |
---|---|
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
1 <?xml version="1.0"?> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
2 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
3 <!-- |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
4 Copyright (C) Nginx, Inc. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
5 --> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
6 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
7 <!DOCTYPE module SYSTEM "../../../../dtd/module.dtd"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
8 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
9 <module name="Module ngx_stream_ssl_module" |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
10 link="/en/docs/stream/ngx_stream_ssl_module.html" |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
11 lang="en" |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
12 rev="20"> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
13 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
14 <section id="summary"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
15 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
16 <para> |
1462
e69e4dbcc760
Documented OSS stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
1456
diff
changeset
|
17 The <literal>ngx_stream_ssl_module</literal> module (1.9.0) |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
18 provides the necessary support for a stream proxy server to work with |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
19 the SSL/TLS protocol. |
1462
e69e4dbcc760
Documented OSS stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
1456
diff
changeset
|
20 This module is not built by default, it should be enabled with the |
e69e4dbcc760
Documented OSS stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
1456
diff
changeset
|
21 <literal>--with-stream_ssl_module</literal> |
e69e4dbcc760
Documented OSS stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
1456
diff
changeset
|
22 configuration parameter. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
23 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
24 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
25 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
26 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
27 |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
28 <section id="example" name="Example Configuration"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
29 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
30 <para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
31 To reduce the processor load, it is recommended to |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
32 <list type="bullet"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
33 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
34 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
35 set the number of |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
36 <link doc="../ngx_core_module.xml" id="worker_processes">worker processes</link> |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
37 equal to the number of processors, |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
38 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
39 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
40 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
41 enable the <link id="ssl_session_cache_shared">shared</link> session cache, |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
42 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
43 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
44 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
45 disable the <link id="ssl_session_cache_builtin">built-in</link> session cache, |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
46 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
47 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
48 <listitem> |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
49 and possibly increase the session <link id="ssl_session_timeout">lifetime</link> |
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
50 (by default, 5 minutes): |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
51 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
52 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
53 </list> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
54 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
55 <example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
56 <emphasis>worker_processes auto;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
57 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
58 stream { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
59 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
60 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
61 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
62 server { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
63 listen 12345 ssl; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
64 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
65 ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
66 ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
67 ssl_certificate /usr/local/nginx/conf/cert.pem; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
68 ssl_certificate_key /usr/local/nginx/conf/cert.key; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
69 <emphasis>ssl_session_cache shared:SSL:10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
70 <emphasis>ssl_session_timeout 10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
71 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
72 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
73 } |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
74 </example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
75 </para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
76 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
77 </section> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
78 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
79 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
80 <section id="directives" name="Directives"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
81 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
82 <directive name="ssl_certificate"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
83 <syntax><value>file</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
84 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
85 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
86 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
87 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
88 <para> |
1456
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
89 Specifies a <value>file</value> with the certificate in the PEM format |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
90 for the given server. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
91 If intermediate certificates should be specified in addition to a primary |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
92 certificate, they should be specified in the same file in the following |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
93 order: the primary certificate comes first, then the intermediate certificates. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
94 A secret key in the PEM format may be placed in the same file. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
95 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
96 |
1726
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
97 <para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
98 Since version 1.11.0, |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
99 this directive can be specified multiple times |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
100 to load certificates of different types, for example, RSA and ECDSA: |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
101 <example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
102 server { |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
103 listen 12345 ssl; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
104 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
105 ssl_certificate example.com.rsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
106 ssl_certificate_key example.com.rsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
107 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
108 ssl_certificate example.com.ecdsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
109 ssl_certificate_key example.com.ecdsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
110 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
111 ... |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
112 } |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
113 </example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
114 <note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
115 Only OpenSSL 1.0.2 or higher supports separate certificate chains |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
116 for different certificates. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
117 With older versions, only one certificate chain can be used. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
118 </note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
119 </para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
120 |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
121 <para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
122 Since version 1.15.9, variables can be used in the <value>file</value> name |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
123 when using OpenSSL 1.0.2 or higher: |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
124 <example> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
125 ssl_certificate $ssl_server_name.crt; |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
126 ssl_certificate_key $ssl_server_name.key; |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
127 </example> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
128 Note that using variables implies that |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
129 a certificate will be loaded for each SSL handshake, |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
130 and this may have a negative impact on performance. |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
131 </para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
132 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
133 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
134 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
135 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
136 <directive name="ssl_certificate_key"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
137 <syntax><value>file</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
138 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
139 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
140 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
141 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
142 <para> |
1456
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
143 Specifies a <value>file</value> with the secret key in the PEM format |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
144 for the given server. |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
145 </para> |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
146 |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
147 <para> |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
148 The value |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
149 <literal>engine</literal>:<value>name</value>:<value>id</value> |
1462
e69e4dbcc760
Documented OSS stream modules.
Vladimir Homutov <vl@nginx.com>
parents:
1456
diff
changeset
|
150 can be specified instead of the <value>file</value>, |
1456
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
151 which loads a secret key with a specified <value>id</value> |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
152 from the OpenSSL engine <value>name</value>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
153 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
154 |
2334
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
155 <para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
156 Since version 1.15.9, variables can be used in the <value>file</value> name |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
157 when using OpenSSL 1.0.2 or higher. |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
158 </para> |
dbe55598d3f6
Added variables support in ssl_certificate and ssl_certificate_key.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
2296
diff
changeset
|
159 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
160 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
161 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
162 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
163 <directive name="ssl_ciphers"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
164 <syntax><value>ciphers</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
165 <default>HIGH:!aNULL:!MD5</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
166 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
167 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
168 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
169 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
170 Specifies the enabled ciphers. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
171 The ciphers are specified in the format understood by the |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
172 OpenSSL library, for example: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
173 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
174 ssl_ciphers ALL:!aNULL:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
175 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
176 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
177 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
178 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
179 The full list can be viewed using the |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
180 “<command>openssl ciphers</command>” command. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
181 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
182 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
183 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
184 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
185 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
186 <directive name="ssl_client_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
187 <syntax><value>file</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
188 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
189 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
190 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
191 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
192 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
193 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
194 Specifies a <value>file</value> with trusted CA certificates in the PEM format |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
195 used to <link id="ssl_verify_client">verify</link> client certificates. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
196 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
197 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
198 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
199 The list of certificates will be sent to clients. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
200 If this is not desired, the <link id="ssl_trusted_certificate"/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
201 directive can be used. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
202 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
203 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
204 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
205 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
206 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
207 <directive name="ssl_crl"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
208 <syntax><value>file</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
209 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
210 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
211 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
212 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
213 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
214 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
215 Specifies a <value>file</value> with revoked certificates (CRL) |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
216 in the PEM format used to <link id="ssl_verify_client">verify</link> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
217 client certificates. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
218 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
219 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
220 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
221 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
222 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
223 <directive name="ssl_dhparam"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
224 <syntax><value>file</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
225 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
226 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
227 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
228 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
229 <para> |
1706
6f5497797cde
Changed "EDH ciphers" to "DHE ciphers".
Maxim Dounin <mdounin@mdounin.ru>
parents:
1521
diff
changeset
|
230 Specifies a <value>file</value> with DH parameters for DHE ciphers. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
231 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
232 |
2296
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
233 <para> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
234 By default no parameters are set, |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
235 and therefore DHE ciphers will not be used. |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
236 <note> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
237 Prior to version 1.11.0, builtin parameters were used by default. |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
238 </note> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
239 </para> |
e2e71f9477a8
Added note about ssl_dhparam defaults.
Sergey Kandaurov <pluknet@nginx.com>
parents:
2068
diff
changeset
|
240 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
241 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
242 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
243 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
244 <directive name="ssl_ecdh_curve"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
245 <syntax><value>curve</value></syntax> |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
246 <default>auto</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
247 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
248 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
249 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
250 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
251 Specifies a <value>curve</value> for ECDHE ciphers. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
252 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
253 |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
254 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
255 When using OpenSSL 1.0.2 or higher, |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
256 it is possible to specify multiple curves (1.11.0), for example: |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
257 <example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
258 ssl_ecdh_curve prime256v1:secp384r1; |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
259 </example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
260 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
261 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
262 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
263 The special value <literal>auto</literal> (1.11.0) instructs nginx to use |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
264 a list built into the OpenSSL library when using OpenSSL 1.0.2 or higher, |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
265 or <literal>prime256v1</literal> with older versions. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
266 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
267 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
268 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
269 <note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
270 Prior to version 1.11.0, |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
271 the <literal>prime256v1</literal> curve was used by default. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
272 </note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
273 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
274 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
275 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
276 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
277 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
278 <directive name="ssl_handshake_timeout"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
279 <syntax><value>time</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
280 <default>60s</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
281 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
282 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
283 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
284 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
285 Specifies a timeout for the SSL handshake to complete. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
286 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
287 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
288 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
289 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
290 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
291 <directive name="ssl_password_file"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
292 <syntax><value>file</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
293 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
294 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
295 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
296 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
297 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
298 Specifies a <value>file</value> with passphrases for |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
299 <link id="ssl_certificate_key">secret keys</link> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
300 where each passphrase is specified on a separate line. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
301 Passphrases are tried in turn when loading the key. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
302 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
303 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
304 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
305 Example: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
306 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
307 stream { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
308 ssl_password_file /etc/keys/global.pass; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
309 ... |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
310 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
311 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
312 listen 127.0.0.1:12345; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
313 ssl_certificate_key /etc/keys/first.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
314 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
315 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
316 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
317 listen 127.0.0.1:12346; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
318 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
319 # named pipe can also be used instead of a file |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
320 ssl_password_file /etc/keys/fifo; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
321 ssl_certificate_key /etc/keys/second.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
322 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
323 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
324 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
325 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
326 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
327 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
328 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
329 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
330 <directive name="ssl_prefer_server_ciphers"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
331 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
332 <default>off</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
333 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
334 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
335 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
336 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
337 Specifies that server ciphers should be preferred over client ciphers |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
338 when the SSLv3 and TLS protocols are used. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
339 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
340 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
341 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
342 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
343 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
344 <directive name="ssl_protocols"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
345 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
346 [<literal>SSLv2</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
347 [<literal>SSLv3</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
348 [<literal>TLSv1</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
349 [<literal>TLSv1.1</literal>] |
1978
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
350 [<literal>TLSv1.2</literal>] |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
351 [<literal>TLSv1.3</literal>]</syntax> |
1499
3687cc9a3592
Removed SSLv3 from the default value of ssl_protocols and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1462
diff
changeset
|
352 <default>TLSv1 TLSv1.1 TLSv1.2</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
353 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
354 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
355 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
356 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
357 Enables the specified protocols. |
1978
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
358 <note> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
359 The <literal>TLSv1.1</literal> and <literal>TLSv1.2</literal> parameters work |
1978
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
360 only when OpenSSL 1.0.1 or higher is used. |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
361 </note> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
362 <note> |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
363 The <literal>TLSv1.3</literal> parameter (1.13.0) works only when |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
364 OpenSSL 1.1.1 built with TLSv1.3 support is used. |
8f1a568a8bbf
Documented "TLSv1.3" parameter of the "ssl_protocols" directive.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1923
diff
changeset
|
365 </note> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
366 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
367 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
368 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
369 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
370 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
371 <directive name="ssl_session_cache"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
372 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
373 <literal>off</literal> | |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
374 <literal>none</literal> | |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
375 [<literal>builtin</literal>[:<value>size</value>]] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
376 [<literal>shared</literal>:<value>name</value>:<value>size</value>]</syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
377 <default>none</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
378 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
379 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
380 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
381 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
382 Sets the types and sizes of caches that store session parameters. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
383 A cache can be of any of the following types: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
384 <list type="tag"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
385 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
386 <tag-name><literal>off</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
387 <tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
388 the use of a session cache is strictly prohibited: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
389 nginx explicitly tells a client that sessions may not be reused. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
390 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
391 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
392 <tag-name><literal>none</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
393 <tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
394 the use of a session cache is gently disallowed: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
395 nginx tells a client that sessions may be reused, but does not |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
396 actually store session parameters in the cache. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
397 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
398 |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
399 <tag-name id="ssl_session_cache_builtin"><literal>builtin</literal></tag-name> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
400 <tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
401 a cache built in OpenSSL; used by one worker process only. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
402 The cache size is specified in sessions. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
403 If size is not given, it is equal to 20480 sessions. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
404 Use of the built-in cache can cause memory fragmentation. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
405 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
406 |
2068
3d9e7993c201
Added links to directives in the example of ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1978
diff
changeset
|
407 <tag-name id="ssl_session_cache_shared"><literal>shared</literal></tag-name> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
408 <tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
409 a cache shared between all worker processes. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
410 The cache size is specified in bytes; one megabyte can store |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
411 about 4000 sessions. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
412 Each shared cache should have an arbitrary name. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
413 A cache with the same name can be used in several |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
414 servers. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
415 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
416 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
417 </list> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
418 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
419 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
420 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
421 Both cache types can be used simultaneously, for example: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
422 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
423 ssl_session_cache builtin:1000 shared:SSL:10m; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
424 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
425 but using only shared cache without the built-in cache should |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
426 be more efficient. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
427 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
428 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
429 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
430 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
431 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
432 <directive name="ssl_session_ticket_key"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
433 <syntax><value>file</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
434 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
435 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
436 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
437 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
438 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
439 Sets a <value>file</value> with the secret key used to encrypt |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
440 and decrypt TLS session tickets. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
441 The directive is necessary if the same key has to be shared between |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
442 multiple servers. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
443 By default, a randomly generated key is used. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
444 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
445 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
446 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
447 If several keys are specified, only the first key is |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
448 used to encrypt TLS session tickets. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
449 This allows configuring key rotation, for example: |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
450 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
451 ssl_session_ticket_key current.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
452 ssl_session_ticket_key previous.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
453 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
454 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
455 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
456 <para> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
457 The <value>file</value> must contain 80 or 48 bytes |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
458 of random data and can be created using the following command: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
459 <example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
460 openssl rand 80 > ticket.key |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
461 </example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
462 Depending on the file size either AES256 (for 80-byte keys, 1.11.8) |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
463 or AES128 (for 48-byte keys) is used for encryption. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
464 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
465 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
466 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
467 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
468 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
469 <directive name="ssl_session_tickets"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
470 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
471 <default>on</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
472 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
473 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
474 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
475 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
476 Enables or disables session resumption through |
1923
66a30a380fba
Fixed links to tools.ietf.org.
Ruslan Ermilov <ru@nginx.com>
parents:
1877
diff
changeset
|
477 <link url="https://tools.ietf.org/html/rfc5077">TLS session tickets</link>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
478 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
479 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
480 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
481 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
482 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
483 <directive name="ssl_session_timeout"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
484 <syntax><value>time</value></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
485 <default>5m</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
486 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
487 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
488 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
489 <para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
490 Specifies a time during which a client may reuse the |
1785
3fa0944ddc6a
Removed info about session cache from ssl_session_timeout.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1745
diff
changeset
|
491 session parameters. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
492 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
493 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
494 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
495 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
496 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
497 <directive name="ssl_trusted_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
498 <syntax><value>file</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
499 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
500 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
501 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
502 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
503 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
504 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
505 Specifies a <value>file</value> with trusted CA certificates in the PEM format |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
506 used to <link id="ssl_verify_client">verify</link> client certificates. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
507 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
508 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
509 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
510 In contrast to the certificate set by <link id="ssl_client_certificate"/>, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
511 the list of these certificates will not be sent to clients. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
512 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
513 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
514 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
515 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
516 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
517 <directive name="ssl_verify_client"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
518 <syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
519 <literal>on</literal> | <literal>off</literal> | |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
520 <literal>optional</literal> | <literal>optional_no_ca</literal></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
521 <default>off</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
522 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
523 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
524 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
525 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
526 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
527 Enables verification of client certificates. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
528 The verification result is stored in the |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
529 <link id="var_ssl_client_verify">$ssl_client_verify</link> variable. |
1876
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
530 If an error has occurred during the client certificate verification |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
531 or a client has not presented the required certificate, |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
532 the connection is closed. |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
533 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
534 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
535 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
536 The <literal>optional</literal> parameter requests the client |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
537 certificate and verifies it if the certificate is present. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
538 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
539 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
540 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
541 The <literal>optional_no_ca</literal> parameter |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
542 requests the client |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
543 certificate but does not require it to be signed by a trusted CA certificate. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
544 This is intended for the use in cases when a service that is external to nginx |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
545 performs the actual certificate verification. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
546 The contents of the certificate is accessible through the |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
547 <link id="var_ssl_client_cert">$ssl_client_cert</link> variable. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
548 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
549 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
550 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
551 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
552 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
553 <directive name="ssl_verify_depth"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
554 <syntax><value>number</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
555 <default>1</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
556 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
557 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
558 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
559 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
560 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
561 Sets the verification depth in the client certificates chain. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
562 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
563 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
564 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
565 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
566 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
567 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
568 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
569 <section id="variables" name="Embedded Variables"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
570 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
571 <para> |
1790
6da8d19f89c0
Corrected module name in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1785
diff
changeset
|
572 The <literal>ngx_stream_ssl_module</literal> module supports variables |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
573 since 1.11.2. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
574 <list type="tag"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
575 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
576 <tag-name id="var_ssl_cipher"><var>$ssl_cipher</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
577 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
578 returns the string of ciphers used |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
579 for an established SSL connection; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
580 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
581 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
582 <tag-name id="var_ssl_ciphers"><var>$ssl_ciphers</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
583 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
584 returns the list of ciphers supported by the client (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
585 Known ciphers are listed by names, unknown are shown in hexadecimal, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
586 for example: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
587 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
588 AES128-SHA:AES256-SHA:0x00ff |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
589 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
590 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
591 The variable is fully supported only when using OpenSSL version 1.0.2 or higher. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
592 With older versions, the variable is available |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
593 only for new sessions and lists only known ciphers. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
594 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
595 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
596 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
597 <tag-name id="var_ssl_client_cert"><var>$ssl_client_cert</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
598 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
599 returns the client certificate in the PEM format |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
600 for an established SSL connection, with each line except the first |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
601 prepended with the tab character (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
602 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
603 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
604 <tag-name id="var_ssl_client_fingerprint"><var>$ssl_client_fingerprint</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
605 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
606 returns the SHA1 fingerprint of the client certificate |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
607 for an established SSL connection (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
608 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
609 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
610 <tag-name id="var_ssl_client_i_dn"><var>$ssl_client_i_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
611 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
612 returns the “issuer DN” string of the client certificate |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
613 for an established SSL connection according to |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
614 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
615 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
616 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
617 <tag-name id="var_ssl_client_raw_cert"><var>$ssl_client_raw_cert</var> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
618 </tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
619 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
620 returns the client certificate in the PEM format |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
621 for an established SSL connection (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
622 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
623 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
624 <tag-name id="var_ssl_client_s_dn"><var>$ssl_client_s_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
625 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
626 returns the “subject DN” string of the client certificate |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
627 for an established SSL connection according to |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
628 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
629 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
630 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
631 <tag-name id="var_ssl_client_serial"><var>$ssl_client_serial</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
632 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
633 returns the serial number of the client certificate |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
634 for an established SSL connection (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
635 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
636 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
637 <tag-name id="var_ssl_client_v_end"><var>$ssl_client_v_end</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
638 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
639 returns the end date of the client certificate (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
640 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
641 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
642 <tag-name id="var_ssl_client_v_remain"><var>$ssl_client_v_remain</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
643 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
644 returns the number of days |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
645 until the client certificate expires (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
646 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
647 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
648 <tag-name id="var_ssl_client_v_start"><var>$ssl_client_v_start</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
649 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
650 returns the start date of the client certificate (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
651 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
652 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
653 <tag-name id="var_ssl_client_verify"><var>$ssl_client_verify</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
654 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
655 returns the result of client certificate verification (1.11.8): |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
656 “<literal>SUCCESS</literal>”, “<literal>FAILED:</literal><value>reason</value>”, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
657 and “<literal>NONE</literal>” if a certificate was not present; |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
658 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
659 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
660 <tag-name id="var_ssl_curves"><var>$ssl_curves</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
661 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
662 returns the list of curves supported by the client (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
663 Known curves are listed by names, unknown are shown in hexadecimal, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
664 for example: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
665 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
666 0x001d:prime256v1:secp521r1:secp384r1 |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
667 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
668 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
669 The variable is supported only when using OpenSSL version 1.0.2 or higher. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
670 With older versions, the variable value will be an empty string. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
671 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
672 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
673 The variable is available only for new sessions. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
674 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
675 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
676 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
677 <tag-name id="var_ssl_protocol"><var>$ssl_protocol</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
678 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
679 returns the protocol of an established SSL connection; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
680 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
681 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
682 <tag-name id="var_ssl_server_name"><var>$ssl_server_name</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
683 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
684 returns the server name requested through |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
685 <link url="http://en.wikipedia.org/wiki/Server_Name_Indication">SNI</link>; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
686 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
687 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
688 <tag-name id="var_ssl_session_id"><var>$ssl_session_id</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
689 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
690 returns the session identifier of an established SSL connection; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
691 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
692 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
693 <tag-name id="var_ssl_session_reused"><var>$ssl_session_reused</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
694 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
695 returns “<literal>r</literal>” if an SSL session was reused, |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
696 or “<literal>.</literal>” otherwise. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
697 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
698 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
699 </list> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
700 </para> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
701 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
702 </section> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
703 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
704 </module> |