Mercurial > hg > nginx
view docs/dtd/change_log_conf.dtd @ 7465:6708bec13757
SSL: adjusted session id context with dynamic certificates.
Dynamic certificates re-introduce problem with incorrect session
reuse (AKA "virtual host confusion", CVE-2014-3616), since there are
no server certificates to generate session id context from.
To prevent this, session id context is now generated from ssl_certificate
directives as specified in the configuration. This approach prevents
incorrect session reuse in most cases, while still allowing sharing
sessions across multiple machines with ssl_session_ticket_key set as
long as configurations are identical.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Mon, 25 Feb 2019 16:42:54 +0300 |
parents | 551102312e19 |
children |
line wrap: on
line source
<!ELEMENT configuration (length, start, indent, changes+) > <!ELEMENT length (#PCDATA) > <!ELEMENT start (#PCDATA) > <!ELEMENT indent (#PCDATA) > <!ELEMENT changes (title, length, bugfix, feature, change, workaround, (month, month, month, month, month, month, month, month, month, month, month, month)?) > <!ATTLIST changes lang ( ru | en) #REQUIRED> <!ELEMENT title (#PCDATA) > <!ELEMENT bugfix (#PCDATA) > <!ELEMENT feature (#PCDATA) > <!ELEMENT change (#PCDATA) > <!ELEMENT workaround (#PCDATA) > <!ELEMENT month (#PCDATA) >