V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
NGINX
NGINX Trac
3rd Party Modules
Security Advisories
CHANGES
OpenResty
ngx_lua
Tengine
在线学习资源
NGINX 开发从入门到精通
NGINX Modules
ngx_echo
alpinefly
V2EX  ›  NGINX

nginx 双向 ssl 认证代码怎么写?

  •  
  •   alpinefly · Jul 15, 2020 · 2473 views
    This topic created in 2112 days ago, the information mentioned may be changed or developed.
    如题,现在代码
    ssl_certificate cert/XX.crt;
    ssl_certificate_key cert/XX.key;
    ssl_trusted_certificate cert/chain.crt;
    双向认证时能用原来的数字证书吗?
    3 replies    2020-07-16 10:03:31 +08:00
    xooass
        1
    xooass  
       Jul 15, 2020

    ssl_client_certificate ssl/cacert.pem;
    ssl_crl ssl/ca.crl;
    ssl_verify_client on;

    双向认证两边的证书是分开,互不关联的,你原来的数字证书那边啥都不用动
    alpinefly
        2
    alpinefly  
    OP
       Jul 15, 2020
    @xooass 个人想使用 免费的邮箱证书,不知道有什么要改,试了半天不行。Sectigo 的免费邮箱证书,ssl_client_certificate 就应该是它的根证书?
    alpinefly
        3
    alpinefly  
    OP
       Jul 16, 2020
    用自签的根证书签发后可以,但是用免费的邮箱证书不行。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   3799 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 43ms · UTC 00:43 · PVG 08:43 · LAX 17:43 · JFK 20:43
    ♥ Do have faith in what you're doing.