Added configurable SSL certificate verification depth and updated the documentation in the code.
This commit is contained in:
@ -356,6 +356,15 @@ This parameter controls the level of encryption used. Accepted values are:
|
|||||||
* TLSv12
|
* TLSv12
|
||||||
* MAX
|
* MAX
|
||||||
|
|
||||||
|
### `ssl_cert_verification_depth`
|
||||||
|
|
||||||
|
The maximum length of the certificate authority chain that will be accepted. Accepted values are positive integers.
|
||||||
|
|
||||||
|
```
|
||||||
|
# Example
|
||||||
|
ssl_cert_verification_depth=10
|
||||||
|
```
|
||||||
|
|
||||||
Example SSL enabled service configuration:
|
Example SSL enabled service configuration:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
@ -8,7 +8,8 @@ Here are the options which relate to SSL and certificates.
|
|||||||
Parameter|Values |Description
|
Parameter|Values |Description
|
||||||
---------|-----------|--------
|
---------|-----------|--------
|
||||||
ssl | disabled, enabled, required |`disable` disables SSL, `enabled` enables SSL for client connections but still allows non-SSL connections and `required` requires SSL from all client connections. With the `required` option, client connections that do not use SSL will be rejected.
|
ssl | disabled, enabled, required |`disable` disables SSL, `enabled` enables SSL for client connections but still allows non-SSL connections and `required` requires SSL from all client connections. With the `required` option, client connections that do not use SSL will be rejected.
|
||||||
ssl_cert | <path to file> |Path to server certificate
|
ssl_cert | path to file |Path to server certificate
|
||||||
ssl_key | <path to file> |Path to server private key
|
ssl_key | path to file |Path to server private key
|
||||||
ssl_ca_cert | <path to file> |Path to Certificate Authority file
|
ssl_ca_cert | path to file |Path to Certificate Authority file
|
||||||
ssl_version|SSLV2,SSLV3,TLSV10,TLSV11,TLSV12,MAX| The SSL method level, defaults to highest available encryption level which is TLSv1.2
|
ssl_version|SSLV2,SSLV3,TLSV10,TLSV11,TLSV12,MAX| The SSL method level, defaults to highest available encryption level which is TLSv1.2
|
||||||
|
ssl_cert_verify_depth|integer|Certificate authority certificate verification depth, default is 100.
|
||||||
|
Reference in New Issue
Block a user