Mercurial > hg > nginx-site
annotate xml/ru/docs/stream/ngx_stream_ssl_module.xml @ 1877:aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Mon, 26 Dec 2016 16:06:26 +0300 |
parents | b451f03e0a4b |
children | 66a30a380fba |
rev | line source |
---|---|
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
1 <?xml version="1.0"?> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
2 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
3 <!-- |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
4 Copyright (C) Nginx, Inc. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
5 --> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
6 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
7 <!DOCTYPE module SYSTEM "../../../../dtd/module.dtd"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
8 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
9 <module name="Модуль ngx_stream_ssl_module" |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
10 link="/ru/docs/stream/ngx_stream_ssl_module.html" |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
11 lang="ru" |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
12 rev="15"> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
13 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
14 <section id="summary"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
15 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
16 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
17 Модуль <literal>ngx_stream_ssl_module</literal> (1.9.0) |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
18 обеспечивает необходимую поддержку для работы |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
19 прокси-сервера по протоколу SSL/TLS. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
20 По умолчанию этот модуль не собирается, его сборку необходимо |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
21 разрешить с помощью конфигурационного параметра |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
22 <literal>--with-stream_ssl_module</literal>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
23 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
24 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
25 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
26 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
27 |
1521
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
28 <section id="example" name="Пример конфигурации"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
29 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
30 <para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
31 Для уменьшения загрузки процессора рекомендуется |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
32 <list type="bullet"> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
33 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
34 <listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
35 установить число рабочих процессов равным числу процессоров, |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
36 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
37 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
38 <listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
39 включить разделяемый кэш сессий, |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
40 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
41 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
42 <listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
43 выключить встроенный кэш сессий |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
44 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
45 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
46 <listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
47 и, возможно, увеличить время жизни сессии (по умолчанию 5 минут): |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
48 </listitem> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
49 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
50 </list> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
51 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
52 <example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
53 <emphasis>worker_processes auto;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
54 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
55 stream { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
56 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
57 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
58 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
59 server { |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
60 listen 12345 ssl; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
61 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
62 ssl_protocols TLSv1 TLSv1.1 TLSv1.2; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
63 ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
64 ssl_certificate /usr/local/nginx/conf/cert.pem; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
65 ssl_certificate_key /usr/local/nginx/conf/cert.key; |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
66 <emphasis>ssl_session_cache shared:SSL:10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
67 <emphasis>ssl_session_timeout 10m;</emphasis> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
68 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
69 ... |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
70 } |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
71 </example> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
72 </para> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
73 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
74 </section> |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
75 |
e3d3e2ed4275
Added example configuration to mail and stream ssl modules.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1520
diff
changeset
|
76 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
77 <section id="directives" name="Директивы"> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
78 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
79 <directive name="ssl_certificate"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
80 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
81 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
82 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
83 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
84 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
85 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
86 Указывает <value>файл</value> с сертификатом в формате PEM |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
87 для данного сервера. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
88 Если вместе с основным сертификатом нужно указать промежуточные, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
89 то они должны находиться в этом же файле в следующем порядке — сначала |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
90 основной сертификат, а затем промежуточные. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
91 В этом же файле может находиться секретный ключ в формате PEM. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
92 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
93 |
1726
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
94 <para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
95 Начиная с версии 1.11.0 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
96 эта директива может быть указана несколько раз |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
97 для загрузки сертификатов разных типов, например RSA и ECDSA: |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
98 <example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
99 server { |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
100 listen 12345 ssl; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
101 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
102 ssl_certificate example.com.rsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
103 ssl_certificate_key example.com.rsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
104 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
105 ssl_certificate example.com.ecdsa.crt; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
106 ssl_certificate_key example.com.ecdsa.key; |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
107 |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
108 ... |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
109 } |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
110 </example> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
111 <note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
112 Возможность задавать отдельные цепочки сертификатов для разных сертификатов |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
113 есть только в OpenSSL 1.0.2 и выше. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
114 Для более старых версий следует указывать только одну цепочку сертификатов. |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
115 </note> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
116 </para> |
a0bc284941f6
Documented multiple certificates support.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1711
diff
changeset
|
117 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
118 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
119 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
120 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
121 <directive name="ssl_certificate_key"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
122 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
123 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
124 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
125 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
126 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
127 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
128 Указывает <value>файл</value> с секретным ключом в формате PEM |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
129 для данного сервера. |
1456
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
130 </para> |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
131 |
acba294382d6
Documented engine support in ssl_certificate_key and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1450
diff
changeset
|
132 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
133 Вместо <value>файла</value> можно указать значение |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
134 <literal>engine</literal>:<value>имя</value>:<value>id</value>, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
135 которое загружает ключ с указанным <value>id</value> |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
136 из OpenSSL engine с заданным <value>именем</value>. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
137 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
138 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
139 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
140 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
141 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
142 <directive name="ssl_ciphers"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
143 <syntax><value>шифры</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
144 <default>HIGH:!aNULL:!MD5</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
145 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
146 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
147 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
148 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
149 Описывает разрешённые шифры. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
150 Шифры задаются в формате, поддерживаемом библиотекой |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
151 OpenSSL, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
152 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
153 ssl_ciphers ALL:!aNULL:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
154 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
155 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
156 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
157 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
158 Полный список можно посмотреть с помощью команды |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
159 “<command>openssl ciphers</command>”. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
160 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
161 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
162 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
163 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
164 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
165 <directive name="ssl_client_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
166 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
167 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
168 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
169 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
170 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
171 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
172 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
173 Указывает <value>файл</value> с доверенными сертификатами CA в формате |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
174 PEM, которые используются для |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
175 <link id="ssl_verify_client">проверки</link> клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
176 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
177 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
178 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
179 Список сертификатов будет отправляться клиентам. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
180 Если это нежелательно, можно воспользоваться директивой |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
181 <link id="ssl_trusted_certificate"/>. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
182 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
183 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
184 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
185 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
186 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
187 <directive name="ssl_crl"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
188 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
189 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
190 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
191 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
192 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
193 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
194 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
195 Указывает <value>файл</value> с отозванными сертификатами (CRL) |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
196 в формате PEM, используемыми для |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
197 <link id="ssl_verify_client">проверки</link> клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
198 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
199 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
200 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
201 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
202 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
203 <directive name="ssl_dhparam"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
204 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
205 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
206 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
207 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
208 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
209 <para> |
1706
6f5497797cde
Changed "EDH ciphers" to "DHE ciphers".
Maxim Dounin <mdounin@mdounin.ru>
parents:
1521
diff
changeset
|
210 Указывает <value>файл</value> с параметрами для DHE-шифров. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
211 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
212 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
213 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
214 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
215 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
216 <directive name="ssl_ecdh_curve"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
217 <syntax><value>кривая</value></syntax> |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
218 <default>auto</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
219 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
220 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
221 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
222 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
223 Задаёт <value>кривую</value> для ECDHE-шифров. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
224 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
225 |
1711
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
226 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
227 При использовании OpenSSL 1.0.2 и выше |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
228 можно указывать несколько кривых (1.11.0), например: |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
229 <example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
230 ssl_ecdh_curve prime256v1:secp384r1; |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
231 </example> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
232 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
233 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
234 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
235 Специальное значение <literal>auto</literal> (1.11.0) соответствует |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
236 встроенному в библиотеку OpenSSL списку кривых для OpenSSL 1.0.2 и выше, |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
237 или <literal>prime256v1</literal> для более старых версий. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
238 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
239 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
240 <para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
241 <note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
242 До версии 1.11.0 |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
243 по умолчанию использовалась кривая <literal>prime256v1</literal>. |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
244 </note> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
245 </para> |
38fb3e6b71e8
Documented ssl_ecdh_curve changes in 1.11.0.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1706
diff
changeset
|
246 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
247 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
248 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
249 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
250 <directive name="ssl_handshake_timeout"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
251 <syntax><value>время</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
252 <default>60s</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
253 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
254 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
255 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
256 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
257 Задаёт таймаут для завершения операции SSL handshake. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
258 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
259 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
260 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
261 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
262 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
263 <directive name="ssl_password_file"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
264 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
265 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
266 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
267 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
268 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
269 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
270 Задаёт <value>файл</value> с паролями от |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
271 <link id="ssl_certificate_key">секретных ключей</link>, |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
272 где каждый пароль указан на отдельной строке. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
273 Пароли применяются по очереди в момент загрузки ключа. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
274 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
275 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
276 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
277 Пример: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
278 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
279 stream { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
280 ssl_password_file /etc/keys/global.pass; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
281 ... |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
282 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
283 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
284 listen 127.0.0.1:12345; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
285 ssl_certificate_key /etc/keys/first.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
286 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
287 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
288 server { |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
289 listen 127.0.0.1:12346; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
290 |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
291 # вместо файла можно указать именованный канал |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
292 ssl_password_file /etc/keys/fifo; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
293 ssl_certificate_key /etc/keys/second.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
294 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
295 } |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
296 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
297 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
298 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
299 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
300 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
301 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
302 <directive name="ssl_prefer_server_ciphers"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
303 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
304 <default>off</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
305 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
306 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
307 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
308 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
309 Указывает, чтобы при использовании протоколов SSLv3 и TLS |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
310 серверные шифры были более приоритетны, чем клиентские. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
311 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
312 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
313 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
314 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
315 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
316 <directive name="ssl_protocols"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
317 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
318 [<literal>SSLv2</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
319 [<literal>SSLv3</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
320 [<literal>TLSv1</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
321 [<literal>TLSv1.1</literal>] |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
322 [<literal>TLSv1.2</literal>]</syntax> |
1499
3687cc9a3592
Removed SSLv3 from the default value of ssl_protocols and friends.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1462
diff
changeset
|
323 <default>TLSv1 TLSv1.1 TLSv1.2</default> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
324 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
325 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
326 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
327 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
328 Разрешает указанные протоколы. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
329 Параметры <literal>TLSv1.1</literal> и <literal>TLSv1.2</literal> работают |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
330 только при использовании библиотеки OpenSSL версии 1.0.1 и выше. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
331 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
332 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
333 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
334 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
335 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
336 <directive name="ssl_session_cache"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
337 <syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
338 <literal>off</literal> | |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
339 <literal>none</literal> | |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
340 [<literal>builtin</literal>[:<value>размер</value>]] |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
341 [<literal>shared</literal>:<value>название</value>:<value>размер</value>]</syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
342 <default>none</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
343 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
344 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
345 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
346 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
347 Задаёт тип и размеры кэшей для хранения параметров сессий. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
348 Тип кэша может быть следующим: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
349 <list type="tag"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
350 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
351 <tag-name><literal>off</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
352 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
353 жёсткое запрещение использования кэша сессий: |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
354 nginx явно сообщает клиенту, что сессии не могут использоваться повторно. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
355 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
356 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
357 <tag-name><literal>none</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
358 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
359 мягкое запрещение использования кэша сессий: |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
360 nginx сообщает клиенту, что сессии могут использоваться повторно, но |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
361 на самом деле не хранит параметры сессии в кэше. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
362 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
363 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
364 <tag-name><literal>builtin</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
365 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
366 встроенный в OpenSSL кэш, используется в рамках только одного рабочего процесса. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
367 Размер кэша задаётся в сессиях. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
368 Если размер не задан, то он равен 20480 сессиям. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
369 Использование встроенного кэша может вести к фрагментации памяти. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
370 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
371 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
372 <tag-name><literal>shared</literal></tag-name> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
373 <tag-desc> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
374 кэш, разделяемый между всеми рабочими процессами. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
375 Размер кэша задаётся в байтах, в 1 мегабайт может поместиться |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
376 около 4000 сессий. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
377 У каждого разделяемого кэша должно быть произвольное название. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
378 Кэш с одинаковым названием может использоваться в нескольких |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
379 серверах. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
380 </tag-desc> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
381 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
382 </list> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
383 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
384 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
385 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
386 Можно использовать одновременно оба типа кэша, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
387 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
388 ssl_session_cache builtin:1000 shared:SSL:10m; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
389 </example> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
390 однако использование только разделяемого кэша без встроенного должно |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
391 быть более эффективным. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
392 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
393 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
394 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
395 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
396 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
397 <directive name="ssl_session_ticket_key"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
398 <syntax><value>файл</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
399 <default/> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
400 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
401 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
402 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
403 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
404 Задаёт <value>файл</value> с секретным ключом, применяемым при шифровании и |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
405 расшифровании TLS session tickets. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
406 Директива необходима, если один и тот же ключ нужно использовать |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
407 на нескольких серверах. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
408 По умолчанию используется случайно сгенерированный ключ. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
409 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
410 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
411 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
412 Если указано несколько ключей, то только первый ключ |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
413 используется для шифрования TLS session tickets. |
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
414 Это позволяет настроить ротацию ключей, например: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
415 <example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
416 ssl_session_ticket_key current.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
417 ssl_session_ticket_key previous.key; |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
418 </example> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
419 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
420 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
421 <para> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
422 <value>Файл</value> должен содержать 80 или 48 байт случайных данных |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
423 и может быть создан следующей командой: |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
424 <example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
425 openssl rand 80 > ticket.key |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
426 </example> |
1877
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
427 В зависимости от размера файла для шифрования будет использоваться либо |
aa29a64a5e9d
Documented ssl_session_ticket_key 80-byte keys.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1876
diff
changeset
|
428 AES256 (для 80-байтных ключей, 1.11.8), либо AES128 (для 48-байтных ключей). |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
429 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
430 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
431 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
432 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
433 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
434 <directive name="ssl_session_tickets"> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
435 <syntax><literal>on</literal> | <literal>off</literal></syntax> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
436 <default>on</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
437 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
438 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
439 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
440 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
441 Разрешает или запрещает возобновление сессий при помощи |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
442 <link url="http://tools.ietf.org/html/rfc5077">TLS session tickets</link>. |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
443 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
444 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
445 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
446 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
447 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
448 <directive name="ssl_session_timeout"> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
449 <syntax><value>время</value></syntax> |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
450 <default>5m</default> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
451 <context>stream</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
452 <context>server</context> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
453 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
454 <para> |
1520
ed36e909bc79
Translated stream_ssl_module into Russian.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1499
diff
changeset
|
455 Задаёт время, в течение которого клиент может повторно |
1785
3fa0944ddc6a
Removed info about session cache from ssl_session_timeout.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1745
diff
changeset
|
456 использовать параметры сессии. |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
457 </para> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
458 |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
459 </directive> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
460 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
461 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
462 <directive name="ssl_trusted_certificate"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
463 <syntax><value>файл</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
464 <default/> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
465 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
466 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
467 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
468 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
469 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
470 Задаёт <value>файл</value> с доверенными сертификатами CA в формате PEM, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
471 которые используются для <link id="ssl_verify_client">проверки</link> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
472 клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
473 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
474 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
475 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
476 В отличие от <link id="ssl_client_certificate"/>, список этих сертификатов |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
477 не будет отправляться клиентам. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
478 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
479 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
480 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
481 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
482 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
483 <directive name="ssl_verify_client"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
484 <syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
485 <literal>on</literal> | <literal>off</literal> | |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
486 <literal>optional</literal> | <literal>optional_no_ca</literal></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
487 <default>off</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
488 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
489 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
490 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
491 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
492 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
493 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
494 Разрешает проверку клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
495 Результат проверки доступен через переменную |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
496 <link id="var_ssl_client_verify">$ssl_client_verify</link>. |
1876
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
497 Если при проверке клиентского сертификата произошла ошибка |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
498 или клиент не предоставил требуемый сертификат, |
b451f03e0a4b
Described behavior of stream ssl_verify_client in case of error.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1869
diff
changeset
|
499 соединение закрывается. |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
500 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
501 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
502 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
503 Параметр <literal>optional</literal> запрашивает клиентский |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
504 сертификат, и если сертификат был предоставлен, проверяет его. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
505 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
506 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
507 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
508 Параметр <literal>optional_no_ca</literal> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
509 запрашивает сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
510 клиента, но не требует, чтобы он был подписан доверенным сертификатом CA. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
511 Это предназначено для случаев, когда фактическая проверка сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
512 осуществляется внешним по отношению к nginx’у сервисом. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
513 Содержимое сертификата доступно через переменную |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
514 <link id="var_ssl_client_cert">$ssl_client_cert</link>. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
515 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
516 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
517 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
518 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
519 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
520 <directive name="ssl_verify_depth"> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
521 <syntax><value>число</value></syntax> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
522 <default>1</default> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
523 <context>stream</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
524 <context>server</context> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
525 <appeared-in>1.11.8</appeared-in> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
526 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
527 <para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
528 Устанавливает глубину проверки в цепочке клиентских сертификатов. |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
529 </para> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
530 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
531 </directive> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
532 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
533 </section> |
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
534 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
535 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
536 <section id="variables" name="Встроенные переменные"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
537 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
538 <para> |
1790
6da8d19f89c0
Corrected module name in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1785
diff
changeset
|
539 Модуль <literal>ngx_stream_ssl_module</literal> поддерживает переменные |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
540 начиная с версии 1.11.2. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
541 <list type="tag"> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
542 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
543 <tag-name id="var_ssl_cipher"><var>$ssl_cipher</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
544 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
545 возвращает строку используемых шифров для установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
546 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
547 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
548 <tag-name id="var_ssl_ciphers"><var>$ssl_ciphers</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
549 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
550 возвращает список шифров, поддерживаемых клиентом (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
551 Известные шифры указаны по имени, неизвестные указаны в шестнадцатеричном виде, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
552 например: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
553 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
554 AES128-SHA:AES256-SHA:0x00ff |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
555 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
556 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
557 Переменная полностью поддерживается при использовании OpenSSL версии 1.0.2 |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
558 и выше. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
559 При использовании более старых версий переменная доступна |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
560 только для новых сессий и может содержать только известные шифры. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
561 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
562 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
563 |
1869
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
564 <tag-name id="var_ssl_client_cert"><var>$ssl_client_cert</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
565 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
566 возвращает клиентский сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
567 для установленного SSL-соединения в формате PEM |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
568 перед каждой строкой которого, кроме первой, вставляется символ табуляции(1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
569 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
570 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
571 <tag-name id="var_ssl_client_fingerprint"><var>$ssl_client_fingerprint</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
572 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
573 возвращает SHA1-отпечаток клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
574 для установленного SSL-соединения (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
575 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
576 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
577 <tag-name id="var_ssl_client_i_dn"><var>$ssl_client_i_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
578 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
579 возвращает строку “issuer DN” клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
580 для установленного SSL-соединения согласно |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
581 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
582 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
583 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
584 <tag-name id="var_ssl_client_raw_cert"><var>$ssl_client_raw_cert</var> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
585 </tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
586 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
587 возвращает клиентский сертификат |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
588 для установленного SSL-соединения в формате PEM (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
589 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
590 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
591 <tag-name id="var_ssl_client_s_dn"><var>$ssl_client_s_dn</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
592 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
593 возвращает строку “subject DN” клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
594 для установленного SSL-соединения согласно |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
595 <link url="https://tools.ietf.org/html/rfc2253">RFC 2253</link> (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
596 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
597 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
598 <tag-name id="var_ssl_client_serial"><var>$ssl_client_serial</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
599 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
600 возвращает серийный номер клиентского сертификата |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
601 для установленного SSL-соединения (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
602 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
603 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
604 <tag-name id="var_ssl_client_v_end"><var>$ssl_client_v_end</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
605 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
606 возвращает дату окончания срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
607 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
608 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
609 <tag-name id="var_ssl_client_v_remain"><var>$ssl_client_v_remain</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
610 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
611 возвращает число дней, |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
612 оставшихся до истечения срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
613 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
614 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
615 <tag-name id="var_ssl_client_v_start"><var>$ssl_client_v_start</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
616 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
617 возвращает дату начала срока действия клиентского сертификата (1.11.8); |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
618 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
619 |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
620 <tag-name id="var_ssl_client_verify"><var>$ssl_client_verify</var></tag-name> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
621 <tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
622 возвращает результат проверки клиентского сертификата (1.11.8): |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
623 “<literal>SUCCESS</literal>”, “<literal>FAILED:</literal><value>reason</value>” |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
624 и, если сертификат не был предоставлен, “<literal>NONE</literal>”; |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
625 </tag-desc> |
e1d0b56c0310
Documented support for client certificate verification in stream.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1857
diff
changeset
|
626 |
1857
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
627 <tag-name id="var_ssl_curves"><var>$ssl_curves</var></tag-name> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
628 <tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
629 возвращает список кривых, поддерживаемых клиентом (1.11.7). |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
630 Известные кривые указаны по имени, неизвестные указаны в шестнадцатеричном виде, |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
631 например: |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
632 <example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
633 0x001d:prime256v1:secp521r1:secp384r1 |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
634 </example> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
635 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
636 Переменная поддерживается при использовании OpenSSL версии 1.0.2 и выше. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
637 При использовании более старых версий значением переменной будет пустая строка. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
638 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
639 <note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
640 Переменная доступна только для новых сессий. |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
641 </note> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
642 </tag-desc> |
0882ccb0c00f
Documented the $ssl_curves and $ssl_ciphers variables.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1790
diff
changeset
|
643 |
1745
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
644 <tag-name id="var_ssl_protocol"><var>$ssl_protocol</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
645 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
646 возвращает протокол установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
647 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
648 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
649 <tag-name id="var_ssl_server_name"><var>$ssl_server_name</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
650 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
651 возвращает имя сервера, запрошенное через |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
652 <link url="http://en.wikipedia.org/wiki/Server_Name_Indication">SNI</link>; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
653 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
654 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
655 <tag-name id="var_ssl_session_id"><var>$ssl_session_id</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
656 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
657 возвращает идентификатор сессии установленного SSL-соединения; |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
658 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
659 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
660 <tag-name id="var_ssl_session_reused"><var>$ssl_session_reused</var></tag-name> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
661 <tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
662 возвращает “<literal>r</literal>”, если сессия была использована повторно, |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
663 иначе “<literal>.</literal>”. |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
664 </tag-desc> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
665 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
666 </list> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
667 </para> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
668 |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
669 </section> |
0dfb7628bfee
Documented variables in ngx_stream_ssl_module.
Yaroslav Zhuravlev <yar@nginx.com>
parents:
1726
diff
changeset
|
670 |
1450
f5b5eefc43cb
Updated commercial docs for the upcoming release.
Ruslan Ermilov <ru@nginx.com>
parents:
diff
changeset
|
671 </module> |