Added configurable SSL certificate verification depth and updated the documentation in the code.
This commit is contained in:
@ -356,6 +356,15 @@ This parameter controls the level of encryption used. Accepted values are:
|
||||
* TLSv12
|
||||
* MAX
|
||||
|
||||
### `ssl_cert_verification_depth`
|
||||
|
||||
The maximum length of the certificate authority chain that will be accepted. Accepted values are positive integers.
|
||||
|
||||
```
|
||||
# Example
|
||||
ssl_cert_verification_depth=10
|
||||
```
|
||||
|
||||
Example SSL enabled service configuration:
|
||||
|
||||
```
|
||||
|
@ -8,7 +8,8 @@ Here are the options which relate to SSL and certificates.
|
||||
Parameter|Values |Description
|
||||
---------|-----------|--------
|
||||
ssl | disabled, enabled, required |`disable` disables SSL, `enabled` enables SSL for client connections but still allows non-SSL connections and `required` requires SSL from all client connections. With the `required` option, client connections that do not use SSL will be rejected.
|
||||
ssl_cert | <path to file> |Path to server certificate
|
||||
ssl_key | <path to file> |Path to server private key
|
||||
ssl_ca_cert | <path to file> |Path to Certificate Authority file
|
||||
ssl_cert | path to file |Path to server certificate
|
||||
ssl_key | path to file |Path to server private key
|
||||
ssl_ca_cert | path to file |Path to Certificate Authority file
|
||||
ssl_version|SSLV2,SSLV3,TLSV10,TLSV11,TLSV12,MAX| The SSL method level, defaults to highest available encryption level which is TLSv1.2
|
||||
ssl_cert_verify_depth|integer|Certificate authority certificate verification depth, default is 100.
|
||||
|
Reference in New Issue
Block a user